CVE-2009-0161
13.05.2009, 15:30
The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified invalid response as a successful OCSP certificate validation, which might allow remote attackers to spoof certificate authentication via a revoked certificate.Enginsight
| Vendor | Product | Version |
|---|---|---|
| apple | mac_os_x | 10.5.0 |
| apple | mac_os_x | 10.5.1 |
| apple | mac_os_x | 10.5.2 |
| apple | mac_os_x | 10.5.3 |
| apple | mac_os_x | 10.5.4 |
| apple | mac_os_x | 10.5.5 |
| apple | mac_os_x | 10.5.6 |
| apple | mac_os_x_server | 10.4.11 |
| apple | mac_os_x_server | 10.5.0 |
| apple | mac_os_x_server | 10.5.1 |
| apple | mac_os_x_server | 10.5.2 |
| apple | mac_os_x_server | 10.5.3 |
| apple | mac_os_x_server | 10.5.4 |
| apple | mac_os_x_server | 10.5.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References