Home / vulnerabilitiesPDF  

Facebook Messenger Certification Validation

Posted on 24 March 2016
Source : packetstormsecurity.org Link

 

Classification: //Dell SecureWorks/Public Use:

Classification: //Dell SecureWorks/Public Use:

Advisory Information
=================
Title: Facebook Messenger (iOS) Certificate Validation Vulnerability
Advisory ID: SWRX-2016-001
Advisory URL: https://www.secureworks.com/research/swrx-2016-001
Date published: Tuesday, March 22, 2016
CVE: Not assigned
CVSS v2 base score: 5.8
Date of last update: Tuesday, March 22, 2016
Vendors contacted: Facebook, Inc.
Release mode: Coordinated
Discovered by: Sean Wright, Dell SecureWorks

Summary
========
The Facebook social networking service includes a mobile application called Messenger that allows users to send private messages to their Facebook contacts. Although the application uses HTTPS to communicate with the backend servers, insufficient validation (only when the device is configured to use a proxy) of the certificates returned by these servers leaves the application open to man-in-the-middle (MITM) attacks.
SecureWorks Europe Limited is registered in England and Wales. Company Registration Number: 9546890 Registered address: Dell House, The Boulevard, Cain Road, Bracknell, Berkshire, RG12 1LF, UK. Company details for other Dell UK entities can be found on www.dell.co.uk.

 

TOP