First published: Mon Nov 15 2010(Updated: )
OpenSSL in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform arithmetic, which allows remote attackers to bypass X.509 certificate authentication via an arbitrary certificate issued by a legitimate Certification Authority.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | >=10.6.0<10.6.5 | |
Apple macOS Server | >=10.6.0<10.6.5 | |
Apple iOS and macOS | =10.6.0 | |
Apple iOS and macOS | =10.6.1 | |
Apple iOS and macOS | =10.6.2 | |
Apple iOS and macOS | =10.6.3 | |
Apple iOS and macOS | =10.6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1378 is considered a medium severity vulnerability due to the potential for bypassing X.509 certificate authentication.
To fix CVE-2010-1378, users should update their Apple Mac OS X to version 10.6.5 or later.
CVE-2010-1378 affects Apple Mac OS X versions 10.6.0 to 10.6.4.
Yes, CVE-2010-1378 can be exploited remotely, allowing attackers to bypass authentication.
Yes, CVE-2010-1378 also affects Apple Mac OS X Server versions 10.6.0 to 10.6.4.