The Data Security component in Apple iOS before 4.2.10 and 4.3.x before 4.3.5 does not check the basicConstraints parameter during validation of X.509 certificate chains, which allows man-in-the-middle attackers to spoof an SSL server by using a non-CA certificate to sign a certificate for an arbitrary domain.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2024-08-06T21:43:15.409Z
Reserved: 2010-12-23T00:00:00
Link: CVE-2011-0228
No data.
Status : Deferred
Published: 2011-08-29T20:55:00.753
Modified: 2025-04-11T00:51:21.963
Link: CVE-2011-0228
No data.
OpenCVE Enrichment
No data.
Weaknesses