Description
Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5130
Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html
Scores
EPSS
0.0144
EPSS Percentile
70.4%
Details
CWE
CWE-310
Status
published
Products (6)
apple/mac_os_x
10.7.0
apple/mac_os_x
10.7.1
apple/mac_os_x
< 10.7.2
apple/mac_os_x_server
10.7.0
apple/mac_os_x_server
10.7.1
apple/mac_os_x_server
< 10.7.2
Published
Feb 02, 2012
Tracked Since
Feb 18, 2026