CFNetwork in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 does not properly validate certificates, which allows remote attackers to spoof trusted SSL certificates via a man-in-the-middle attack.
| Software | From | Fixed in |
|---|---|---|
| apple / mac_os_x | 10.4.3 | 10.4.3.x |
| apple / mac_os_x | 10.4.1 | 10.4.1.x |
| apple / mac_os_x | 10.4.9 | 10.4.9.x |
| apple / mac_os_x | 10.4.7 | 10.4.7.x |
| apple / mac_os_x | 10.4.4 | 10.4.4.x |
| apple / mac_os_x | 10.4.6 | 10.4.6.x |
| apple / mac_os_x | 10.4.5 | 10.4.5.x |
| apple / mac_os_x | 10.4.8 | 10.4.8.x |
| apple / mac_os_x | 10.4.2 | 10.4.2.x |