libsecurity in Apple Mac OS X before 10.7.4 accesses uninitialized memory locations during the processing of X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted certificate.
Metrics
No CVSS v4.0
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
Vendors | Products |
---|---|
Apple |
|
Configuration 1 [-]
|
Configuration 2 [-]
|
No data.
References
History
No history.

Status: PUBLISHED
Assigner: apple
Published:
Updated: 2024-08-06T18:30:53.819Z
Reserved: 2012-01-12T00:00:00
Link: CVE-2012-0654

No data.

Status : Modified
Published: 2012-05-11T03:49:58.887
Modified: 2024-11-21T01:35:28.257
Link: CVE-2012-0654

No data.