CVE-2009-0161: Input Validation
The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified invalid response as a successful OCSP certificate validation, which might allow remote attackers to spoof certificate authentication via a revoked certificate.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0161?
CVE-2009-0161 is classified as a moderate severity vulnerability affecting the OpenSSL::OCSP module in specific versions of Apple macOS.
How do I fix CVE-2009-0161?
To fix CVE-2009-0161, update your Apple macOS to versions 10.5.7 or later.
Which systems are affected by CVE-2009-0161?
CVE-2009-0161 affects Apple macOS versions 10.5.0 through 10.5.6 and macOS Server versions 10.4.11 through 10.5.6.
What type of attack does CVE-2009-0161 allow?
CVE-2009-0161 allows remote attackers to spoof certificate authentication by misinterpreting revoked certificates.
Is CVE-2009-0161 specific to macOS?
Yes, CVE-2009-0161 is specific to Apple macOS and macOS Server environments.