Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8gjh-39j4-6x54

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Secure Transport in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 does not ensure that a DTLS message is accepted only for a DTLS connection, which allows remote attackers to obtain potentially sensitive information from uninitialized process memory by providing a DTLS message within a TLS connection.

Secure Transport in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 does not ensure that a DTLS message is accepted only for a DTLS connection, which allows remote attackers to obtain potentially sensitive information from uninitialized process memory by providing a DTLS message within a TLS connection.

EPSS

Процентиль: 73%
0.00783
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
больше 11 лет назад

Secure Transport in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 does not ensure that a DTLS message is accepted only for a DTLS connection, which allows remote attackers to obtain potentially sensitive information from uninitialized process memory by providing a DTLS message within a TLS connection.

EPSS

Процентиль: 73%
0.00783
Низкий

Дефекты

CWE-200