Description
CFNetwork in Apple Mac OS X 10.6.3 and 10.6.4 supports anonymous SSL and TLS connections, which allows man-in-the-middle attackers to redirect a connection and obtain sensitive information via crafted responses.
Affected products
- Apple / cfnetwork
- Apple / mac_os_x10.6.3 – 10.6.3
- Apple / mac_os_x10.6.4 – 10.6.4
- Apple / mac_os_x_server10.6.3 – 10.6.3
- Apple / mac_os_x_server10.6.4 – 10.6.4