Apple iOS Calendar Synchronization SSL Certificate Validation Information Disclosure Vulnerability
BID:50149
Info
Apple iOS Calendar Synchronization SSL Certificate Validation Information Disclosure Vulnerability
| Bugtraq ID: | 50149 |
| Class: | Unknown |
| CVE: |
CVE-2011-3253 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2011 12:00AM |
| Updated: | Oct 12 2011 12:00AM |
| Credit: | Leszek Tasiemski of nSense |
| Vulnerable: |
Apple iPod Touch 0 Apple iPhone 0 Apple iPad 0 Apple iOS 4.2.1 Apple iOS 4.0.2 Apple iOS 4.0.1 Apple iOS 3.2.2 Apple iOS 3.2.1 Apple iOS 4.3.5 Apple iOS 4.3.4 Apple iOS 4.3.3 Apple iOS 4.3.2 Apple iOS 4.3.1 Apple iOS 4.3 Apple iOS 4.2.9 Apple iOS 4.2.8 Apple iOS 4.2.7 Apple iOS 4.2.6 Apple iOS 4.2.5 Apple iOS 4.2.10 Apple iOS 4.2 Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 Apple iOS 3.1 Apple iOS 3.0 |
| Not Vulnerable: |
Apple iOS 5 |
Discussion
Apple iOS Calendar Synchronization SSL Certificate Validation Information Disclosure Vulnerability
Apple iOS is prone to an information-disclosure vulnerability that affects the calendar synchronization feature.
Attackers can exploit this issue to obtain sensitive information from CalDAV communications.
An attacker can exploit this issue through man-in-the-middle attacks by impersonating a trusted server. This may allow the attacker to obtain credentials or other sensitive information or give users a false sense of security. Information harvested may aid in further attacks.
NOTE: This issue was previously discussed in BID 50086 (Apple iPhone/iPad/iPod touch Prior to iOS 5 Multiple Vulnerabilities) but has been given its own record to better document it
Apple iOS is prone to an information-disclosure vulnerability that affects the calendar synchronization feature.
Attackers can exploit this issue to obtain sensitive information from CalDAV communications.
An attacker can exploit this issue through man-in-the-middle attacks by impersonating a trusted server. This may allow the attacker to obtain credentials or other sensitive information or give users a false sense of security. Information harvested may aid in further attacks.
NOTE: This issue was previously discussed in BID 50086 (Apple iPhone/iPad/iPod touch Prior to iOS 5 Multiple Vulnerabilities) but has been given its own record to better document it
Exploit / POC
Apple iOS Calendar Synchronization SSL Certificate Validation Information Disclosure Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Apple iOS Calendar Synchronization SSL Certificate Validation Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Apple iOS Calendar Synchronization SSL Certificate Validation Information Disclosure Vulnerability
References:
References: