Full Disclosure mailing list archives

Facebook Messenger (iOS) Certificate Validation Vulnerability


From: Sean Wright <swright () secureworks com>
Date: Wed, 23 Mar 2016 12:01:13 +0000

Classification: //Dell SecureWorks/Public Use:

Classification: //Dell SecureWorks/Public Use:

Advisory Information
=================
Title: Facebook Messenger (iOS) Certificate Validation Vulnerability
Advisory ID: SWRX-2016-001
Advisory URL: https://www.secureworks.com/research/swrx-2016-001
Date published: Tuesday, March 22, 2016
CVE: Not assigned
CVSS v2 base score: 5.8
Date of last update: Tuesday, March 22, 2016
Vendors contacted: Facebook, Inc.
Release mode: Coordinated
Discovered by: Sean Wright, Dell SecureWorks

Summary
========
The Facebook social networking service includes a mobile application called Messenger that allows users to send private 
messages to their Facebook contacts. Although the application uses HTTPS to communicate with the backend servers, 
insufficient validation (only when the device is configured to use a proxy) of the certificates returned by these 
servers leaves the application open to man-in-the-middle (MITM) attacks.
SecureWorks Europe Limited is registered in England and Wales. Company Registration Number: 9546890 Registered address: 
Dell House, The Boulevard, Cain Road, Bracknell, Berkshire, RG12 1LF, UK. Company details for other Dell UK entities 
can be found on www.dell.co.uk.

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/


Current thread: