CVE-2010-3831: Infoleak
Photos in Apple iOS before 4.2 enables support for HTTP Basic Authentication over an unencrypted connection, which allows man-in-the-middle attackers to read MobileMe account passwords by spoofing a MobileMe Gallery server during a "Send to MobileMe" action.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3831?
CVE-2010-3831 has a moderate severity rating, which indicates potential risk to user credentials.
How do I fix CVE-2010-3831?
To mitigate CVE-2010-3831, users are advised to update their Apple iOS to a version that is not vulnerable.
What type of attack does CVE-2010-3831 enable?
CVE-2010-3831 enables man-in-the-middle attacks that can expose MobileMe account passwords.
Which versions of iOS are affected by CVE-2010-3831?
CVE-2010-3831 affects several iOS versions including 3.0, 3.1.3, 3.2, and earlier versions up to 4.1.
What is the primary risk of CVE-2010-3831?
The primary risk of CVE-2010-3831 is the exposure of sensitive user information, specifically MobileMe account credentials.