The Certificate Trust Policy component in Apple Mac OS X...
Moderate severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Feb 9, 2024
Description
Published by the National Vulnerability Database
Jun 24, 2011
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Feb 9, 2024
The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a revoked certificate.
References