FaceTime in Apple iOS before 4.1 on the iPhone and iPod touch does not properly handle invalid X.509 certificates, which allows man-in-the-middle attackers to redirect calls via a crafted certificate.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html | vendor advisory |
http://support.apple.com/kb/HT4334 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/61695 | vdb entry |