O
penSSL in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform arithmetic, which allows remote attackers to bypass X.509 certificate authentication via an arbitrary certificate issued by a legitimate Certification Authority.
References
| Link | Resource |
|---|---|
| http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html | Mailing List |
| http://support.apple.com/kb/HT4435 | Broken Link Patch Vendor Advisory |
| http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html | Mailing List |
| http://support.apple.com/kb/HT4435 | Broken Link Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:14
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html - Mailing List | |
| References | () http://support.apple.com/kb/HT4435 - Broken Link, Patch, Vendor Advisory |
Information
Published : 2010-11-15 23:00
Updated : 2025-04-11 00:51
NVD link : CVE-2010-1378
Mitre link : CVE-2010-1378
CVE.ORG link : CVE-2010-1378
JSON object : View
Products Affected
CWE
CWE-295
Improper Certificate Validation