Security Advisory

CVE-2011-3224

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2011-10-14 10:00:00
Last updated 2024-08-06 23:29:56
Assigner apple
State PUBLISHED

Description

The User Documentation component in Apple Mac OS X through 10.6.8 uses http sessions for updates to App Store help information, which allows man-in-the-middle attackers to execute arbitrary code by spoofing the http server.