Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-3427

Overview

Vulnerability Score 2.6 2.6
CVE Id CVE-2011-3427
Last Modified 30 Oct 2013 11:19:19
Published 14 Oct 2011 06:55:10
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity HIGH
Authentication NONE

CVE-2011-3427

Summary

The Data Security component in Apple iOS before 5 and Apple TV before 4.4 does not properly restrict use of the MD5 hash algorithm within X.509 certificates, which makes it easier for man-in-the-middle attackers to spoof servers or obtain sensitive information via a crafted certificate.

Vulnerable Systems

Operating System

  • Apple Iphone Os 3.0

  • Apple Iphone Os 3.1

  • Apple Iphone Os 3.1.2

  • Apple Iphone Os 3.1.3

  • Apple Iphone Os 3.2

  • Apple Iphone Os 3.2.1

  • Apple Iphone Os 3.2.2

  • Apple Iphone Os 4.0

  • Apple Iphone Os 4.0.1

  • Apple Iphone Os 4.0.2

  • Apple Iphone Os 4.1

  • Apple Iphone Os 4.2.1

  • Apple Iphone Os 4.2.5

  • Apple Iphone Os 4.2.8

  • Apple Iphone Os 4.3.0

  • Apple Iphone Os 4.3.1

  • Apple Iphone Os 4.3.2

  • Apple Iphone Os 4.3.3

  • Apple Iphone Os 4.3.5

Application

  • Apple Tv 4.0

  • Apple Tv 4.1

  • Apple Tv 4.2

  • Apple Tv 4.3


References

XF - appleios-appletv-x509-spoofing(70547)

CONFIRM - http://support.apple.com/kb/HT5001

CONFIRM - http://support.apple.com/kb/HT4999

OSVDB - 76326

APPLE - APPLE-SA-2011-10-12-2

APPLE - APPLE-SA-2011-10-12-1

APPLE - APPLE-SA-2013-10-22-3


Last Updated: 27 May 2016 11:03:38