Vulnerability CVE-2010-1802


Published: 2010-08-25   Modified: 2012-02-13

Description:
libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name strings in X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a certificate associated with a similar domain name, as demonstrated by use of a www.example.con certificate to spoof www.example.com.

Type:

CWE-287

(Improper Authentication)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.4/10
4.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None
Affected software
Apple -> Libsecurity 
Apple -> Mac os x 
Apple -> Mac os x server 

 References:
http://support.apple.com/kb/HT4312
http://securitytracker.com/id?1024359
http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html

Copyright 2021, cxsecurity.com

 

Back to Top