CVE-2011-3444
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD
Description
Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.
Affected (6)
Products: Apple: Mac Os X, Mac Os X Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10.7.2 | |
| Up to 10.7.2 |
Related CWEs
References (4)
Source: product-security@apple.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.