CVE-2014-5957
Description
The Alien War Survivors (aka com.ly.a13.gp) application 1.3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Alien War Survivors for Android (version 1.3.1) fails to validate SSL certificates, allowing man-in-the-middle attackers to intercept sensitive data.
Vulnerability
The Alien War Survivors application (com.ly.a13.gp) version 1.3.1 for Android does not properly verify X.509 certificates from SSL servers [1]. This means the app accepts any certificate presented during an HTTPS connection, including self-signed or forged certificates, without checking the chain of trust.
Exploitation
An attacker positioned on the same network as the victim (e.g., on a public Wi-Fi) can perform a man-in-the-middle attack. By presenting a crafted certificate, the attacker can intercept the HTTPS connection between the app and its server. No additional authentication or user interaction is required beyond the victim using the app over the compromised network.
Impact
Successful exploitation allows the attacker to view and modify network traffic that should have been protected by HTTPS. This can lead to disclosure of sensitive information transmitted by the app, such as login credentials or personal data. In some cases, arbitrary code execution may be possible if the app processes attacker-controlled data [1].
Mitigation
No official patch has been released for version 1.3.1. The CERT/CC recommends not using affected applications and instead accessing the same content via a web browser, which typically implements proper SSL validation [1]. Users should uninstall the app until a fix is available.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- cpe:2.3:a:linkyungame:alien_war_survivors:1.3.1:*:*:*:*:android:*:*
- Range: = 1.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.kb.cert.org/vuls/id/582497nvdThird Party AdvisoryUS Government Resource
- www.kb.cert.org/vuls/id/816929nvdUS Government Resource
- docs.google.com/spreadsheets/d/1t5GXwjw82SyunALVJb2w0zi3FoLRIkfGPc7AMjRF0r4/editnvd
News mentions
0No linked articles in our index yet.