CVE-2011-0228: Input Validation
The Data Security component in Apple iOS before 4.2.10 and 4.3.x before 4.3.5 does not check the basicConstraints parameter during validation of X.509 certificate chains, which allows man-in-the-middle attackers to spoof an SSL server by using a non-CA certificate to sign a certificate for an arbitrary domain.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0228?
CVE-2011-0228 has a high severity rating due to its potential for man-in-the-middle attacks.
How do I fix CVE-2011-0228?
To fix CVE-2011-0228, users should upgrade to iOS version 4.2.10 or later.
What does CVE-2011-0228 affect?
CVE-2011-0228 affects multiple versions of Apple iOS, specifically those before 4.2.10 and 4.3.x before 4.3.5.
What is the impact of exploiting CVE-2011-0228?
Exploitation of CVE-2011-0228 allows attackers to spoof SSL servers using non-CA certificates.
Is CVE-2011-0228 related to X.509 certificate chains?
Yes, CVE-2011-0228 involves improper validation of X.509 certificate chains due to basicConstraints parameter checks.