CVE-2015-3996 Information
Feb 14, 2021
cve
Description
The default AFSecurityPolicy.validatesDomainName configuration for AFSSLPinningModeNone in the AFNetworking framework before 2.5.3 as used in the ownCloud iOS Library disables verification of a server hostname against the domain name in the subject’s Common Name (CN) of the X.509 certificate which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Reference
http://www.securityfocus.com/bid/76242 https://github.com/AFNetworking/AFNetworking/issues/2619 https://github.com/AFNetworking/AFNetworking/releases/tag/2.5.3 https://owncloud.org/security/advisory/?id=oc-sa-2015-012
Share on: