Apple iTunes before 11.0.3 does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
                
            References
                    Configurations
                    Configuration 1 (hide)
| AND | 
                                
                                
 
  | 
                        
Information
                Published : 2013-05-20 07:44
Updated : 2018-10-30 09:25
NVD link : CVE-2013-1014
Mitre link : CVE-2013-1014
JSON object : View
CWE
                
                    
                        
                        CWE-20
                        
            Improper Input Validation
Products Affected
                apple
- itunes
 - mac_os_x
 
microsoft
- windows_7
 - windows_vista
 - windows_xp
 


