[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[FD] Facebook Messenger (iOS) Certificate Validation Vulnerability
- To: "fulldisclosure@xxxxxxxxxxxx" <fulldisclosure@xxxxxxxxxxxx>
- Subject: [FD] Facebook Messenger (iOS) Certificate Validation Vulnerability
- From: Sean Wright <swright@xxxxxxxxxxxxxxx>
- Date: Wed, 23 Mar 2016 12:01:13 +0000
Classification: //Dell SecureWorks/Public Use:
Classification: //Dell SecureWorks/Public Use:
Advisory Information
=================
Title: Facebook Messenger (iOS) Certificate Validation Vulnerability
Advisory ID: SWRX-2016-001
Advisory URL: https://www.secureworks.com/research/swrx-2016-001
Date published: Tuesday, March 22, 2016
CVE: Not assigned
CVSS v2 base score: 5.8
Date of last update: Tuesday, March 22, 2016
Vendors contacted: Facebook, Inc.
Release mode: Coordinated
Discovered by: Sean Wright, Dell SecureWorks
Summary
========
The Facebook social networking service includes a mobile application called
Messenger that allows users to send private messages to their Facebook
contacts. Although the application uses HTTPS to communicate with the backend
servers, insufficient validation (only when the device is configured to use a
proxy) of the certificates returned by these servers leaves the application
open to man-in-the-middle (MITM) attacks.
SecureWorks Europe Limited is registered in England and Wales. Company
Registration Number: 9546890 Registered address: Dell House, The Boulevard,
Cain Road, Bracknell, Berkshire, RG12 1LF, UK. Company details for other Dell
UK entities can be found on www.dell.co.uk.
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/