7.5
CVSSv2

CVE-2011-0228

Published: 29/08/2011 Updated: 10/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Data Security component in Apple iOS prior to 4.2.10 and 4.3.x prior to 4.3.5 does not check the basicConstraints parameter during validation of X.509 certificate chains, which allows man-in-the-middle malicious users to spoof an SSL server by using a non-CA certificate to sign a certificate for an arbitrary domain.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple iphone os 4.2.1

apple iphone os 3.2.1

apple iphone os 3.2

apple iphone os 2.1.1

apple iphone os 2.1

apple iphone os 1.1.3

apple iphone os 1.1.2

apple iphone os

apple iphone os 4.0

apple iphone os 3.2.2

apple iphone os 3.0

apple iphone os 2.2.1

apple iphone os 2.2

apple iphone os 1.1.5

apple iphone os 1.1.4

apple iphone os 1.0.0

apple iphone os 4.2.8

apple iphone os 4.0.2

apple iphone os 4.0.1

apple iphone os 3.1

apple iphone os 3.0.1

apple iphone os 2.0.0

apple iphone os 2.0

apple iphone os 1.0.2

apple iphone os 1.0.1

apple iphone os 4.2.5

apple iphone os 4.1

apple iphone os 3.1.3

apple iphone os 3.1.2

apple iphone os 2.0.2

apple iphone os 2.0.1

apple iphone os 1.1.1

apple iphone os 1.1.0

apple iphone os 4.3.4

apple iphone os 4.3.2

apple iphone os 4.3.3

apple iphone os 4.3.0

apple iphone os 4.3.1

Github Repositories

CVE-2011-0228 fix for older idevices/firmwares

iOS < 435 fix for SSL vulnerability (CVE-2011-0228) Changelog v12 : DigiNotar blacklist v11 : fix repeated leaf false positives bug v10 : initial release Deb packages githubcom/jan0/isslfix/downloads 83aa7a01f4377d3e5ec2e1af9c99602a isslfix_12deb 12 cydia package daa5c6efae5b36690153e715712e265e isslfix_11deb 11 package on cydia (same as fix