CalDAV in Apple iOS before 5 does not validate X.509 certificates for SSL sessions, which allows man-in-the-middle attackers to spoof calendar servers and obtain sensitive information via an arbitrary certificate.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html | vendor advisory |
http://support.apple.com/kb/HT4999 | vendor advisory |