← Back

CVE-2012-3698

nvd nist
Published: Jul 26, 2012Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Apple Xcode before 4.4 does not properly compose a designated requirement (DR) during signing of programs that lack bundle identifiers, which allows remote attackers to read keychain entries via a crafted app, as demonstrated by the keychain entries of a (1) helper tool or (2) command-line tool.

Affected (27)

Products: Apple: Xcode
1 product
Xcode
Configuration A
27 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Up to 4.3.3
Version 1.5.0
Version 2.0.0
Version 2.1.0
Version 2.2.0
Version 2.3.0
Version 2.4.0
Version 2.4.1
Version 3.1.1
Version 3.1.2
Version 3.1.3
Version 3.1.4
Version 3.1
Version 3.2.1
Version 3.2.2
Version 3.2.3
Version 3.2.4
Version 3.2.5
Version 4.0.1
Version 4.0.2
Version 4.0
Version 4.1.1
Version 4.2.1
Version 4.2
Version 4.3.1
Version 4.3.2
Version 4.3

Related CWEs

References (2)

Source: product-security@apple.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.