CVE Database
/

CVE-2011-0228

Back to search

CVE-2011-0228

Published: Aug 29, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

The Data Security component in Apple iOS before 4.2.10 and 4.3.x before 4.3.5 does not check the basicConstraints parameter during validation of X.509 certificate chains, which allows man-in-the-middle attackers to spoof an SSL server by using a non-CA certificate to sign a certificate for an arbitrary domain.

VendorProductVersions

n/a

n/a

affected
n/a

References

APPLE-SA-2011-07-25-1
vendor-advisory
x_refsource_APPLE
48877
vdb-entry
x_refsource_BID
45369
third-party-advisory
x_refsource_SECUNIA
APPLE-SA-2011-07-25-2
vendor-advisory
x_refsource_APPLE
8361
third-party-advisory
x_refsource_SREASON
1025837
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now