Security Advisory

CVE-2013-3948

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2013-06-05 10:00:00
Last updated 2024-08-06 16:30:48
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Apple iOS 6.1.3 does not follow redirects during determination of the hostname to display in an iOS Enterprise Deployment installation dialog, which makes it easier for remote attackers to trigger installation of arbitrary applications via a download-manifest itms-services:// URL that leverages an open redirect vulnerability within a trusted domain.