CFNetwork in Apple Mac OS X 10.5 before 10.5.7 does not properly parse noncompliant Set-Cookie headers, which allows remote attackers to obtain sensitive information by sniffing the network for "secure cookies" that are sent over unencrypted HTTP connections.
Weaknesses in this category are typically introduced during the configuration of the software.
Link | Tags |
---|---|
http://support.apple.com/kb/HT3549 | patch vendor advisory |
http://secunia.com/advisories/35074 | third party advisory |
http://www.securitytracker.com/id?1022214 | vdb entry |
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html | patch vendor advisory |
http://www.securityfocus.com/bid/34926 | vdb entry |
http://www.us-cert.gov/cas/techalerts/TA09-133A.html | third party advisory us government resource |
http://www.vupen.com/english/advisories/2009/1297 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/50479 | vdb entry |