CVE-2012-3698: Medium severity Apple Xcode vulnerability
Apple Xcode before 4.4 does not properly compose a designated requirement (DR) during signing of programs that lack bundle identifiers, which allows remote attackers to read keychain entries via a crafted app, as demonstrated by the keychain entries of a (1) helper tool or (2) command-line tool.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3698?
CVE-2012-3698 has a moderate severity level due to the potential for remote attackers to exploit it to read sensitive keychain entries.
How do I fix CVE-2012-3698?
To mitigate CVE-2012-3698, upgrade to Apple Xcode 4.4 or later, which includes the necessary patches.
What versions of Xcode are affected by CVE-2012-3698?
CVE-2012-3698 affects Apple Xcode versions prior to 4.4, including all versions from 1.5.0 to 4.3.2.
What is the impact of CVE-2012-3698 on keychain security?
CVE-2012-3698 allows attackers to potentially read sensitive keychain entries from applications lacking proper bundle identifiers.
Can CVE-2012-3698 be exploited without user interaction?
Yes, remote attackers can exploit CVE-2012-3698 through a crafted application without requiring user interaction.