Total vulnerabilities in the database
The X.509 certificate-trust implementation in Apple iOS before 9.1 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate.
Software | From | Fixed in |
---|---|---|
apple / iphone_os | - | 9.0.2.x |
apple / watchos | - | 2.0.x |