Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-2234

Опубликовано: 05 мар. 2014
Источник: nvd
CVSS2: 6.4
EPSS Низкий

Описание

A certain Apple patch for OpenSSL in Apple OS X 10.9.2 and earlier uses a Trust Evaluation Agent (TEA) feature without terminating certain TLS/SSL handshakes as specified in the SSL_CTX_set_verify callback function's documentation, which allows remote attackers to bypass extra verification within a custom application via a crafted certificate chain that is acceptable to TEA but not acceptable to that application.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
Версия до 10.9.2 (включая)

EPSS

Процентиль: 30%
0.00111
Низкий

6.4 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

debian
почти 12 лет назад

A certain Apple patch for OpenSSL in Apple OS X 10.9.2 and earlier use ...

github
больше 3 лет назад

A certain Apple patch for OpenSSL in Apple OS X 10.9.2 and earlier uses a Trust Evaluation Agent (TEA) feature without terminating certain TLS/SSL handshakes as specified in the SSL_CTX_set_verify callback function's documentation, which allows remote attackers to bypass extra verification within a custom application via a crafted certificate chain that is acceptable to TEA but not acceptable to that application.

EPSS

Процентиль: 30%
0.00111
Низкий

6.4 Medium

CVSS2

Дефекты

CWE-20