Security Advisory

CVE-2010-1377

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2010-06-17 16:00:00
Last updated 2024-09-16 18:19:44
Assigner apple
CVSS score not scored
State PUBLISHED

Description

Open Directory in Apple Mac OS X 10.6 before 10.6.4 creates an unencrypted connection upon certain SSL failures, which allows man-in-the-middle attackers to spoof arbitrary network account servers, and possibly execute arbitrary code, via unspecified vectors.