The Security Framework in Apple Mac OS X 10.3.9, and 10.4.x before 10.4.7, does not properly search certificate revocation lists (CRL), which allows remote attackers to access systems by using revoked certificates.
| Software | From | Fixed in |
|---|---|---|
| apple / mac_os_x | 10.4.3 | 10.4.3.x |
| apple / mac_os_x | 10.4.1 | 10.4.1.x |
| apple / mac_os_x | 10.4.4 | 10.4.4.x |
| apple / mac_os_x | 10.4 | 10.4.x |
| apple / mac_os_x | 10.4.6 | 10.4.6.x |
| apple / mac_os_x | 10.4.5 | 10.4.5.x |
| apple / mac_os_x | 10.3.9 | 10.3.9.x |
| apple / mac_os_x | 10.4.2 | 10.4.2.x |