The Pizza Hut Japan Official Order application before 1.1.1.a for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2013-06-10T17:00:00Z

Updated: 2024-09-17T02:56:48.381Z

Reserved: 2013-05-22T00:00:00Z

Link: CVE-2013-3641

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2013-06-10T17:55:01.617

Modified: 2014-03-05T19:11:16.290

Link: CVE-2013-3641

cve-icon Redhat

No data.