Title: Apple Mac OS X Security Framework Crafted X.509 Certificate Handling Remote DoS
Info
Disclosure
Nov 14, 2006
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Unknown
Description
Mac OS X contains a flaw that may allow a local denial of service. The issue is triggered when validating a specially crafted X.509 certificate containing a public key that could consume a significant amount of system resources during signature verification, and will result in loss of availability for the platform.
Classification
Location:
Local Access Required,
Remote / Network Access
Attack Type:
Cryptographic,
Denial of Service
Impact:
Loss of Integrity,
Loss of Availability
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, Apple has released a patch to address this vulnerability.