libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation list (CRL), which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) a crafted (1) web site or (2) e-mail message.
Metrics
No CVSS v4.0
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
Vendors | Products |
---|---|
Apple |
|
Configuration 1 [-]
|
No data.
References
History
No history.

Status: PUBLISHED
Assigner: apple
Published:
Updated: 2024-08-06T23:29:56.155Z
Reserved: 2011-08-19T00:00:00
Link: CVE-2011-3227

No data.

Status : Modified
Published: 2011-10-14T10:55:09.277
Modified: 2024-11-21T01:30:01.653
Link: CVE-2011-3227

No data.