ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/11322 | vdb entry |
http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html | patch vendor advisory |