First published: Sat Dec 02 2017(Updated: )
Calculator. Exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.
Credit: Richard Shupak (linkedin.com/in/rshupak) Seth Vargo @sethvargo Google an anonymous researcher product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <11.2 | |
Apple iOS | <11.2 | 11.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2017-2411.
The severity of CVE-2017-2411 is medium, with a severity value of 5.9.
The affected software is Apple iOS up to version 11.2.
This vulnerability was addressed by enabling HTTPS for exchange rates in iOS 11.2.
You can find more information about this vulnerability in the following references: [Apple Support - HT208334](https://support.apple.com/HT208334) and [Apple Support - HT208334 (en-US)](https://support.apple.com/en-us/HT208334).