Security Advisory

CVE-2011-3422

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2011-09-10 00:00:00
Last updated 2024-08-06 23:37:47
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The Keychain implementation in Apple Mac OS X 10.6.8 and earlier does not properly handle an untrusted attribute of a Certification Authority certificate, which makes it easier for man-in-the-middle attackers to spoof arbitrary SSL servers via an Extended Validation certificate, as demonstrated by https access with Safari.