{ "id": "CVE-2011-3253", "sourceIdentifier": "product-security@apple.com", "published": "2011-10-14T10:55:09.887", "lastModified": "2024-11-21T01:30:06.823", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "CalDAV in Apple iOS before 5 does not validate X.509 certificates for SSL sessions, which allows man-in-the-middle attackers to spoof calendar servers and obtain sensitive information via an arbitrary certificate." }, { "lang": "es", "value": "CalDAV en Apple iOS antes de v5 no valida los certificados X.509 para las sesiones de SSL, lo que permite a atacantes de tipo hombre-en-el-medio (\"man-in-the-middle\") falsificar los servidores de calendario y obtener informaci\u00f3n sensible a trav\u00e9s de un certificado de su elecci\u00f3n." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N", "baseScore": 2.6, "accessVector": "NETWORK", "accessComplexity": "HIGH", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE" }, "baseSeverity": "LOW", "exploitabilityScore": 4.9, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-200" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:3.0:-:iphone:*:*:*:*:*", "matchCriteriaId": "A066B59B-D5C8-4AA8-9CC7-5D34F4AB88AA" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:3.1:*:*:*:*:*:*:*", "matchCriteriaId": "51D3BE2B-5A01-4AD4-A436-0056B50A535D" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:3.1:-:iphone:*:*:*:*:*", "matchCriteriaId": "E357722F-4976-4E47-BFB5-709480BAE267" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:3.1:-:ipodtouch:*:*:*:*:*", "matchCriteriaId": "F43A6FEC-ECA9-44A4-AD00-FDC6F3990DC0" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:3.1.2:-:iphone:*:*:*:*:*", "matchCriteriaId": "7CA92907-90C9-4BD6-8EE8-8FA6298C3D0F" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:3.1.3:-:iphone:*:*:*:*:*", "matchCriteriaId": "220590DA-2B6A-4FC9-B456-3053EED9D96E" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:3.2:-:iphone:*:*:*:*:*", "matchCriteriaId": "3FE3CDE8-6497-445E-A845-8A1C2A4EDEB1" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:3.2:-:ipodtouch:*:*:*:*:*", "matchCriteriaId": "9E4D3134-28BC-4C30-A9B0-559338FBBDFD" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:3.2.1:*:*:*:*:*:*:*", "matchCriteriaId": "3A939B80-0AD0-48AF-81A7-370716F56639" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:3.2.1:-:ipad:*:*:*:*:*", "matchCriteriaId": "98C41674-370B-4CF0-817B-3843D93A10DA" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:3.2.2:*:*:*:*:*:*:*", "matchCriteriaId": "D28528CE-4943-4F82-80C0-A629DA3E6702" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:4.0:*:*:*:*:*:*:*", "matchCriteriaId": "12E22AF0-2B66-425A-A1EE-4F0E3B0433E7" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:4.0:-:iphone:*:*:*:*:*", "matchCriteriaId": "954CDDCB-AC22-448D-8ECA-CFA4DBA1BC27" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:4.0:-:ipodtouch:*:*:*:*:*", "matchCriteriaId": "54FECD66-4216-43FC-9959-B8EA9545449C" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:4.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "BB34ECBE-33E8-40E1-936B-7800D2525AE6" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:4.0.1:-:iphone:*:*:*:*:*", "matchCriteriaId": "ECE983F6-A597-4581-A254-80396B54F2D5" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:4.0.1:-:ipodtouch:*:*:*:*:*", "matchCriteriaId": "586C0CB3-98E5-4CB3-8F23-27F01233D6C4" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:4.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "107C59BE-D8CF-4A17-8DFB-BED2AB12388D" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:4.1:*:*:*:*:*:*:*", "matchCriteriaId": "36C86BB9-0328-4E34-BC2B-47B3471EC262" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:4.2.1:*:*:*:*:*:*:*", "matchCriteriaId": "A54A8681-2D8A-4B0B-A947-82F3CE1FB03C" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:4.2.5:*:*:*:*:*:*:*", "matchCriteriaId": "E0070D83-2E27-4DA8-8D10-A6A697216F36" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:4.2.8:*:*:*:*:*:*:*", "matchCriteriaId": "8C9ACA63-4528-4090-B1EA-1FE57A6B0555" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:4.3.0:*:*:*:*:*:*:*", "matchCriteriaId": "7252935C-E421-4339-B61F-0299E28888DA" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:4.3.1:*:*:*:*:*:*:*", "matchCriteriaId": "9DD342BF-096A-4082-B700-19629F2BDE87" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:4.3.2:*:*:*:*:*:*:*", "matchCriteriaId": "93141AB6-26F2-4C6D-95B3-D383EABB4034" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:4.3.3:*:*:*:*:*:*:*", "matchCriteriaId": "4D5C61FF-7CD3-410A-94F2-5DE701466B1F" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:4.3.5:*:*:*:*:*:*:*", "matchCriteriaId": "28A01C87-B02A-4239-8340-B396D0E6B21C" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:4.3.5:-:ipad:*:*:*:*:*", "matchCriteriaId": "396634C5-774C-4131-B927-3CAD239EF0B3" }, { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:4.3.5:-:ipodtouch:*:*:*:*:*", "matchCriteriaId": "64FF0F29-B3C2-4BDC-89FF-DBEDE87D64A4" } ] } ] } ], "references": [ { "url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html", "source": "product-security@apple.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://support.apple.com/kb/HT4999", "source": "product-security@apple.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://support.apple.com/kb/HT4999", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] } ] }