iChat in Apple Mac OS X 10.5 before 10.5.7 disables SSL for AOL Instant Messenger (AIM) communication in certain circumstances that are inconsistent with the Require SSL setting, which allows remote attackers to obtain sensitive information by sniffing the network.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
http://support.apple.com/kb/HT3549 | patch vendor advisory |
http://secunia.com/advisories/35074 | third party advisory broken link |
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html | patch vendor advisory mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/50487 | third party advisory vdb entry |
http://www.securityfocus.com/bid/34926 | broken link third party advisory vdb entry |
http://www.securitytracker.com/id?1022212 | broken link third party advisory vdb entry |
http://www.us-cert.gov/cas/techalerts/TA09-133A.html | third party advisory us government resource |
http://www.vupen.com/english/advisories/2009/1297 | vdb entry broken link |