Back

MEDIUM

The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a revoked certificate

Published Jun 24, 2011

Description

The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a revoked certificate.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apple
Published Jun 24, 2011
Updated Jan 21, 2025
Reserved Dec 23, 2010
CISA Vulnrichment
Updated Feb 9, 2024
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a