PT-2006-5212 · Apple · Macos X
Timothy J. Miller
·
Published
2006-11-30
·
Updated
2011-03-08
·
CVE-2006-4409
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Mac OS X versions 10.4 through 10.4.8
Description
The issue concerns the Online Certificate Status Protocol (OCSP) service in the Security Framework, which retrieves certificate revocation lists (CRL) when an HTTP proxy is in use. This could lead to the system accepting certificates that have been revoked.
Recommendations
For Mac OS X versions 10.4 through 10.4.8, consider disabling the use of HTTP proxies for OCSP services until a fix is available. Restrict access to the OCSP service to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Macos X