CVE-2014-4449 Information

Description

iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Reference

http://secunia.com/advisories/61825 http://www.securityfocus.com/archive/1/533747 http://www.securityfocus.com/bid/70659 http://www.securitytracker.com/id/1031077 https://exchange.xforce.ibmcloud.com/vulnerabilities/97665 https://support.apple.com/kb/HT6541

Share on: