First published: Thu Aug 06 2009(Updated: )
CFNetwork in Apple Mac OS X 10.5 before 10.5.8 places an incorrect URL in a certificate warning in certain 302 redirection scenarios, which makes it easier for remote attackers to trick a user into visiting an arbitrary https web site by leveraging an open redirect vulnerability, a different issue than CVE-2009-2062.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | =10.5.2-2008-002 | |
Apple Mac OS X Server | =10.5.2 | |
Apple Mac OS X | =10.5.6 | |
Apple Mac OS X | =10.5.5 | |
Apple Mac OS X Server | =10.5.5 | |
Apple Mac OS X | =10.5.1 | |
Apple Mac OS X Server | =10.5.1 | |
Apple Mac OS X Server | =10.5.6 | |
Apple Mac OS X | =10.5.3 | |
Apple Mac OS X | =10.5.0 | |
Apple Mac OS X Server | =10.5.0 | |
Apple Mac OS X Server | =10.5.3 | |
Apple Mac OS X | =10.5 | |
Apple Mac OS X Server | =10.5.4 | |
Apple Mac OS X | =10.5.2 | |
Apple Mac OS X Server | =10.5.7 | |
Apple Mac OS X | =10.5.6 | |
Apple Mac OS X | =10.5.7 | |
Apple Mac OS X Server | =10.5 | |
Apple Mac OS X | =10.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.