First published: Thu Feb 02 2012(Updated: )
Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X Server | <=10.7.2 | |
Apple Mac OS X Server | =10.7.1 | |
Apple Mac OS X Server | =10.7.0 | |
Apple Mac OS X | =10.7.0 | |
Apple Mac OS X | <=10.7.2 | |
Apple Mac OS X | =10.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.