Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-77w5-p2v7-hh9q

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The X.509 certificate-trust implementation in Apple OS X before 10.11 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate.

The X.509 certificate-trust implementation in Apple OS X before 10.11 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate.

EPSS

Процентиль: 37%
0.00157
Низкий

Связанные уязвимости

nvd
больше 10 лет назад

The X.509 certificate-trust implementation in Apple OS X before 10.11 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate.

fstec
больше 10 лет назад

Уязвимость операционной системы Mac OS X, позволяющая нарушителю проводить атаки типа "человек по середине"

EPSS

Процентиль: 37%
0.00157
Низкий