CVE-2014-1295
23.04.2014, 11:52
Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple TV before 6.1.1 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack."Enginsight
Vendor | Product | Version |
---|---|---|
apple | iphone_os | 𝑥 ≤ 7.1 |
apple | iphone_os | 7.0 |
apple | iphone_os | 7.0.1 |
apple | iphone_os | 7.0.2 |
apple | iphone_os | 7.0.3 |
apple | iphone_os | 7.0.4 |
apple | iphone_os | 7.0.5 |
apple | iphone_os | 7.0.6 |
apple | mac_os_x | 10.9 |
apple | mac_os_x | 10.9.1 |
apple | mac_os_x | 10.9.2 |
apple | tvos | 𝑥 ≤ 6.1 |
apple | tvos | 6.0 |
apple | tvos | 6.0.1 |
apple | tvos | 6.0.2 |
apple | mac_os_x | 10.8.0 |
apple | mac_os_x | 10.8.1 |
apple | mac_os_x | 10.8.2 |
apple | mac_os_x | 10.8.3 |
apple | mac_os_x | 10.8.4 |
apple | mac_os_x | 10.8.5 |
apple | mac_os_x | 10.8.5:supplemental_update |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References