CVE-2010-1377: Critical severity apple ios and macos vulnerability
Published Jun 17, 2010
·Updated
Open Directory in Apple Mac OS X 10.6 before 10.6.4 creates an unencrypted connection upon certain SSL failures, which allows man-in-the-middle attackers to spoof arbitrary network account servers, and possibly execute arbitrary code, via unspecified vectors.
Affected Software
8 affected components
Apple Mac OS X Server=10.6.3
Apple iOS and macOS=10.6.3
Apple Mac OS X Server=10.6.1
Apple Mac OS X Server=10.6.2
Apple iOS and macOS=10.6.1
Apple Mac OS X Server=10.6.0
Apple iOS and macOS=10.6.0
Apple iOS and macOS=10.6.2
Remediation
Patch Available
Patch Available
Event History
Jun 17, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-1377?
CVE-2010-1377 has a moderate severity level due to the potential for man-in-the-middle attacks.
2
How do I fix CVE-2010-1377?
To fix CVE-2010-1377, update your Apple Mac OS X to version 10.6.4 or later.
3
What systems are affected by CVE-2010-1377?
CVE-2010-1377 affects Apple Mac OS X versions 10.6.0 to 10.6.3.
4
What type of attack does CVE-2010-1377 facilitate?
CVE-2010-1377 facilitates man-in-the-middle attacks that can spoof network account servers.
5
Can CVE-2010-1377 allow arbitrary code execution?
Yes, CVE-2010-1377 can potentially allow arbitrary code execution through unspecified vectors.