An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Security" component. It allows remote attackers to bypass intended certificate-trust restrictions via a revoked X.509 certificate.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/100992 | vdb entry third party advisory |
https://support.apple.com/HT208144 | vendor advisory |
http://www.securitytracker.com/id/1039427 | vdb entry third party advisory |
https://support.apple.com/HT208113 | vendor advisory |
https://support.apple.com/HT208112 | vendor advisory |
https://support.apple.com/HT208115 | vendor advisory |