News: Apple Releases iOS 4.3.5

Posted on July 25, 2011

Just ten days after iOS 4.3.4, Apple released iOS 4.3.5 for iPhone 3GS, iPhone 4 (GSM), iPod touch, and iPad users, and 4.2.10 for the iPhone 4 (CDMA). This update fixes a security vulnerability with certificate validation.

The fix is said to include the following:

Impact: An attacker with a privileged network position may capture or modify data in sessions protected by SSL/TLS

Description: A certificate chain validation issue existed in the handling of X.509 certificates. An attacker with a privileged network position may capture or modify data in sessions protected by SSL/TLS. Other attacks involving X.509 certificate validation may also be possible. This issue is addressed through improved validation of X.509 certificate chains.

This post has been filed in News