Skip to content

Latest commit

 

History

History
17 lines (11 loc) · 753 Bytes

CVE-2011-0228.md

File metadata and controls

17 lines (11 loc) · 753 Bytes

Description

The Data Security component in Apple iOS before 4.2.10 and 4.3.x before 4.3.5 does not check the basicConstraints parameter during validation of X.509 certificate chains, which allows man-in-the-middle attackers to spoof an SSL server by using a non-CA certificate to sign a certificate for an arbitrary domain.

POC

Reference

No PoCs from references.

Github