Release date:
Updated on:
Affected Systems:
Facebook Camera for iOS <1.1.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57153
Facebook Camera is a mobile app for sharing images on Facebook on iOS.
In versions earlier than Facebook Camera 1.1.2, server SSL certificates were not correctly verified. Through man-in-the-middle attacks, attackers can hijack user accounts and passwords on wifi, resulting in information leakage.
<* Source: Mohamed Ramadan
Link: http://secunia.com/advisories/51699/
Http://techcrunch.com/2012/12/24/security-loophole-in-facebooks-camera-app-allowed-hackers-to-hijack-accounts-over-wifi/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Facebook
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.facebook.com/