Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL server for the (1) POP3, (2) IMAP, or (3) SMTP protocol via an arbitrary valid certificate.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/78620 | third party advisory vdb entry |
http://www.securityfocus.com/bid/55569 | broken link third party advisory vdb entry |
http://www.kb.cert.org/vuls/id/389795 | third party advisory us government resource |
http://osvdb.org/85619 | vdb entry broken link |
http://www.securitytracker.com/id?1027541 | broken link third party advisory vdb entry |