Apple Mac OS X CFNetwork Anonymous SSL/TLS Connections Information Disclosure Vulnerability
BID:42651
Info
Apple Mac OS X CFNetwork Anonymous SSL/TLS Connections Information Disclosure Vulnerability
| Bugtraq ID: | 42651 |
| Class: | Design Error |
| CVE: |
CVE-2010-1800 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 24 2010 12:00AM |
| Updated: | Aug 24 2010 12:00AM |
| Credit: | Bjurman of Sirius IT, Jean-Luc Giraud of Citrix, and Aaron Sigel of vtty.com |
| Vulnerable: |
Apple Mac OS X Server 10.6.4 Apple Mac OS X Server 10.6.3 Apple Mac OS X Server 10.6.2 Apple Mac OS X Server 10.6.1 Apple Mac OS X Server 10.6 Apple Mac OS X 10.6.4 Apple Mac OS X 10.6.3 Apple Mac OS X 10.6.2 Apple Mac OS X 10.6.1 Apple Mac OS X 10.6 |
| Not Vulnerable: | |
Discussion
Apple Mac OS X CFNetwork Anonymous SSL/TLS Connections Information Disclosure Vulnerability
Apple Mac OS X is prone to an information-disclosure vulnerability that exists in the CFNetwork component.
An attacker can exploit this issue to redirect connections and intercept user credentials or other sensitive information. This may lead to other attacks.
This issue does not affect the Apple Mail application.
Mac OS X 10.6.4, Mac OS X Server 10.6.4 and prior are vulnerable.
Apple Mac OS X is prone to an information-disclosure vulnerability that exists in the CFNetwork component.
An attacker can exploit this issue to redirect connections and intercept user credentials or other sensitive information. This may lead to other attacks.
This issue does not affect the Apple Mail application.
Mac OS X 10.6.4, Mac OS X Server 10.6.4 and prior are vulnerable.
Exploit / POC
Apple Mac OS X CFNetwork Anonymous SSL/TLS Connections Information Disclosure Vulnerability
An attacker can exploit this issue by using readily available network utilities.
An attacker can exploit this issue by using readily available network utilities.
Solution / Fix
Apple Mac OS X CFNetwork Anonymous SSL/TLS Connections Information Disclosure Vulnerability
Solution:
Vendor fixes are available. Please see the referenced advisory for details.
Apple Mac OS X 10.6.4
Solution:
Vendor fixes are available. Please see the referenced advisory for details.
Apple Mac OS X 10.6.4
-
Apple SecUpd2010-005Snow.dmg
For Mac OS X v10.6.4
http://www.apple.com/support/downloads/
References
Apple Mac OS X CFNetwork Anonymous SSL/TLS Connections Information Disclosure Vulnerability
References:
References:
- Mac OS X Homepage (Apple)