Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-1802

Опубликовано: 25 авг. 2010
Источник: nvd
CVSS2: 6.4
EPSS Низкий

Описание

libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name strings in X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a certificate associated with a similar domain name, as demonstrated by use of a www.example.con certificate to spoof www.example.com.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:apple:libsecurity:*:*:*:*:*:*:*:*

Одно из

cpe:2.3:o:apple:mac_os_x:10.5.8:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.6.4:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.5.8:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.6.4:*:*:*:*:*:*:*

EPSS

Процентиль: 31%
0.00119
Низкий

6.4 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

github
больше 3 лет назад

libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name strings in X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a certificate associated with a similar domain name, as demonstrated by use of a www.example.con certificate to spoof www.example.com.

EPSS

Процентиль: 31%
0.00119
Низкий

6.4 Medium

CVSS2

Дефекты

CWE-287