Back to search
CVE-2013-1014
Published: May 19, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
Apple iTunes before 11.0.3 does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
oval:org.mitre.oval:def:17605
vdb-entry
signature
x_refsource_OVAL
http://support.apple.com/kb/HT5766
x_refsource_CONFIRM
APPLE-SA-2013-05-16-1
vendor-advisory
x_refsource_APPLE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now