Security Advisory

CVE-2016-0818

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2016-03-12 21:00:00
Last updated 2024-08-05 22:30:04
Assigner google_android
CVSS score not scored
State PUBLISHED

Description

The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 mishandles the distinction between an intermediate CA and a trusted root CA, which allows man-in-the-middle attackers to spoof servers by leveraging access to an intermediate CA to issue a certificate, aka internal bug 26232830.