Safari on Apple iPhone before 2.0 and iPod touch before 2.0 misinterprets a menu button press as user confirmation for visiting a web site with a (1) self-signed or (2) invalid certificate, which makes it easier for remote attackers to spoof web sites.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/43734 | vdb entry |
http://www.securityfocus.com/bid/30186 | vdb entry |
http://jvn.jp/en/jp/JVN88676089/index.html | third party advisory |
http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html | vendor advisory |
http://www.vupen.com/english/advisories/2008/2094/references | vdb entry |
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000039.html | third party advisory |
http://secunia.com/advisories/31074 | third party advisory |