4.3
CVSSv2

CVE-2011-3422

Published: 12/09/2011 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Keychain implementation in Apple Mac OS X 10.6.8 and previous versions does not properly handle an untrusted attribute of a Certification Authority certificate, which makes it easier for man-in-the-middle malicious users to spoof arbitrary SSL servers via an Extended Validation certificate, as demonstrated by https access with Safari.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x 10.6.2

apple mac os x 10.6.3

apple mac os x 10.6.6

apple mac os x 10.6.7

apple mac os x 10.6.0

apple mac os x 10.6.1

apple mac os x

apple mac os x 10.6.4

apple mac os x 10.6.5

apple mac os x server

apple mac os x server 10.6.6

apple mac os x server 10.6.5

apple mac os x server 10.6.2

apple mac os x server 10.6.1

apple mac os x server 10.6.0

apple mac os x server 10.6.7

apple mac os x server 10.6.3

apple mac os x server 10.6.4