← Back

CVE-2011-3422

nvd nist
Published: Sep 12, 2011Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The Keychain implementation in Apple Mac OS X 10.6.8 and earlier does not properly handle an untrusted attribute of a Certification Authority certificate, which makes it easier for man-in-the-middle attackers to spoof arbitrary SSL servers via an Extended Validation certificate, as demonstrated by https access with Safari.

Affected (18)

2 products
Mac Os X
Mac Os X Server
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Up to 10.6.8
Version 10.6.0
Version 10.6.1
Version 10.6.2
Version 10.6.3
Version 10.6.4
Version 10.6.5
Version 10.6.6
Version 10.6.7
Configuration B
9 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Up to 10.6.8
Version 10.6.0
Version 10.6.1
Version 10.6.2
Version 10.6.3
Version 10.6.4
Version 10.6.5
Version 10.6.6
Version 10.6.7

Timeline

No history available yet.