CVE-2017-2387

Publication date

2017-04-07 11:12:00

Family

apple

State

PUBLISHED

Description

The Apple Music (aka com.apple.android.music) application before 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.