CVE-2010-1377

Publication date

2010-06-17 16:00:00

Family

apple

State

PUBLISHED

Description

Open Directory in Apple Mac OS X 10.6 before 10.6.4 creates an unencrypted connection upon certain SSL failures, which allows man-in-the-middle attackers to spoof arbitrary network account servers, and possibly execute arbitrary code, via unspecified vectors.