SpiceBoy Публикувано Юли 25, 2011 Публикувано Юли 25, 2011 Fixes a security vulnerability with certificate validation. Цитирай
iPhoneman Публикувано Юли 25, 2011 Публикувано Юли 25, 2011 (редактирано) И всъщност какво значи този Fix ? От Аппле искат да кажат, че със нов сертификат, който слагаш на телефона примерно може да го хакнеш ? Много грубо звучи, не знам. Аз си слагам за VPN, но си ги правя аз. Интересно е да се пробва, но някой да подскаже за какво точно става въпрос ако знае... ЕДИТ: Това било.. SummaryThis document describes the security content of iOS 4.3.5, which can be downloaded and installed using iTunes. For the protection of our customers, Apple does not disclose, discuss, or confirm security issues until a full investigation has occurred and any necessary patches or releases are available. To learn more about Apple Product Security, see the Apple Product Security website. For information about the Apple Product Security PGP Key, see "How to use the Apple Product Security PGP Key." Where possible, CVE IDs are used to reference the vulnerabilities for further information. To learn about other Security Updates, see "Apple Security Updates". iOS 4.3.5 Software UpdateData Security Available for: iOS 3.0 through 4.3.4 for iPhone 3GS and iPhone 4 (GSM), iOS 3.1 through 4.3.4 for iPod touch (3rd generation) and later, iOS 3.2 through 4.3.4 for iPad Impact: An attacker with a privileged network position may capture or modify data in sessions protected by SSL/TLS Description: A certificate chain validation issue existed in the handling of X.509 certificates. An attacker with a privileged network position may capture or modify data in sessions protected by SSL/TLS. Other attacks involving X.509 certificate validation may also be possible. This issue is addressed through improved validation of X.509 certificate chains. CVE-ID CVE-2011-0228 : Gregor Kopf of Recurity Labs on behalf of BSI, and Paul Kehrer of Trustwave's SpiderLabs Редактирано Юли 25, 2011 от iPhoneman Цитирай
Recommended Posts
Присъединете се към разговора
Можете да публикувате сега и да се регистрирате по-късно. Ако имате акаунт, влезте сега да публикувате с вашия акаунт.