The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors related to lack of an HTTPS session for retrieving updates.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce/2016/Sep/msg00008.html | vendor advisory |
http://www.securitytracker.com/id/1036797 | vdb entry |
http://lists.apple.com/archives/security-announce/2016/Sep/msg00002.html | vendor advisory mailing list |
http://www.securityfocus.com/bid/92932 | vdb entry |
https://support.apple.com/HT207143 | vendor advisory |