6.4
CVSSv2

CVE-2010-1802

Published: 25/08/2010 Updated: 26/08/2010
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name strings in X.509 certificates, which allows man-in-the-middle malicious users to spoof SSL servers via a certificate associated with a similar domain name, as demonstrated by use of a www.example.con certificate to spoof www.example.com.

Vulnerable Product Search on Vulmon Subscribe to Product

apple libsecurity

apple mac_os_x_server 10.5.8

apple mac_os_x 10.6.4

apple mac_os_x_server 10.6.4

apple mac_os_x 10.5.8