First published: Thu Oct 24 2013(Updated: )
The ldapsearch command-line program in OpenLDAP in Apple Mac OS X before 10.9 does not properly process the minssf configuration setting, which allows remote attackers to obtain sensitive information by leveraging unintended weak encryption and sniffing the network.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <=10.8.5 | |
Apple Mac OS X | =10.8.0 | |
Apple Mac OS X | =10.8.1 | |
Apple Mac OS X | =10.8.2 | |
Apple Mac OS X | =10.8.3 | |
Apple Mac OS X | =10.8.4 | |
Apple Mac OS X | =10.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.