PT-2011-4447 · Apple · Macos X+1
Published
2011-09-10
·
Updated
2017-08-29
·
CVE-2011-3422
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Apple Mac OS X versions 10.6.8 and earlier
Description
The issue arises from the Keychain implementation not properly handling an untrusted attribute of a Certification Authority certificate. This makes it easier for man-in-the-middle attackers to spoof arbitrary SSL servers via an Extended Validation certificate. For example, this could be demonstrated by accessing a website via HTTPS with Safari.
Recommendations
For Apple Mac OS X versions 10.6.8 and earlier, consider updating to a newer version to mitigate the risk of man-in-the-middle attacks. As a temporary workaround, restrict access to untrusted Certification Authority certificates to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Macos X
Safari