OSVDB ID: 30731

Title: Apple Mac OS X Security Framework Secure Transport Cipher Negotiation Weakness

Info

Disclosure

Nov 14, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Mac OS X contains a flaw that may allow the Security Framework to negotiate a weaker cipher than is available. It is possible that the flaw may allow less secure communications resulting in a loss of confidentiality.

Classification

Location: Remote / Network Access
Attack Type: Cryptographic
Impact: Loss of Confidentiality
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Upgrade to version 10.4.8 or higher, as it has been reported to fix this vulnerability. In addition, Apple has released a patch for version 10.3.9.

Products

Apple Computer, Inc.

Mac OS X

10.3.x

References

Credit

  • Eric Cronin -


Direct URL: http://osvdb.org/30731