[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FD] Facebook Messenger (iOS) Certificate Validation Vulnerability



Classification: //Dell SecureWorks/Public Use:

Classification: //Dell SecureWorks/Public Use:

Advisory Information
=================
Title: Facebook Messenger (iOS) Certificate Validation Vulnerability
Advisory ID: SWRX-2016-001
Advisory URL: https://www.secureworks.com/research/swrx-2016-001
Date published: Tuesday, March 22, 2016
CVE: Not assigned
CVSS v2 base score: 5.8
Date of last update: Tuesday, March 22, 2016
Vendors contacted: Facebook, Inc.
Release mode: Coordinated
Discovered by: Sean Wright, Dell SecureWorks

Summary
========
The Facebook social networking service includes a mobile application called 
Messenger that allows users to send private messages to their Facebook 
contacts. Although the application uses HTTPS to communicate with the backend 
servers, insufficient validation (only when the device is configured to use a 
proxy) of the certificates returned by these servers leaves the application 
open to man-in-the-middle (MITM) attacks.
SecureWorks Europe Limited is registered in England and Wales. Company 
Registration Number: 9546890 Registered address: Dell House, The Boulevard, 
Cain Road, Bracknell, Berkshire, RG12 1LF, UK. Company details for other Dell 
UK entities can be found on www.dell.co.uk.

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/