Apple simply says the update “fixes a security vulnerability with certificate validation.”
Update: Apple has now posted a document outlining the security fix in this release. They code the issue as “CVE-2011-0228”
Impact: An attacker with a privileged network position may capture or modify data in sessions protected by SSL/TLS
Description: A certificate chain validation issue existed in the handling of X.509 certificates. An attacker with a privileged network position may capture or modify data in sessions protected by SSL/TLS. Other attacks involving X.509 certificate validation may also be possible. This issue is addressed through improved validation of X.509 certificate chains.
You can download it via iTunes with your iDevice plugged in, or just grab the ipsw files from the direct links below. The build number of iOS 4.3.5 is 8L1 and the build for 4.2.10 (CDMA) is 8E600