CVE-2016-6231: Infoleak
Published Aug 25, 2016
·Updated
Kaspersky Safe Browser iOS before 1.7.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information via a crafted certificate.
Affected Software
1 affected component
Kaspersky Safe Browser Iphone Os<=1.6.0
Event History
Aug 25, 2016
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6231?
CVE-2016-6231 is considered a high-severity vulnerability due to the potential for man-in-the-middle attacks that can expose sensitive data.
2
How do I fix CVE-2016-6231?
To resolve CVE-2016-6231, upgrade Kaspersky Safe Browser to version 1.7.0 or later.
3
What types of attacks are possible due to CVE-2016-6231?
CVE-2016-6231 allows man-in-the-middle attackers to intercept and access sensitive information via a rogue SSL certificate.
4
Which versions of Kaspersky Safe Browser are affected by CVE-2016-6231?
CVE-2016-6231 affects Kaspersky Safe Browser versions prior to 1.7.0.
5
What can I do if I must use an affected version of Kaspersky Safe Browser?
If you must use an affected version of Kaspersky Safe Browser, consider using an alternative security solution until you can upgrade.