Java for Mac OS X 10.5 before Update 6 and 10.6 before Update 1 accepts expired certificates for applets, which makes it easier for remote attackers to execute arbitrary code via an applet.
Weaknesses in this category are related to the design and implementation of data confidentiality and integrity. Frequently these deal with the use of encoding techniques, encryption libraries, and hashing algorithms. The weaknesses in this category could lead to a degradation of the quality data if they are not addressed.
Link | Tags |
---|---|
http://support.apple.com/kb/HT3970 | patch vendor advisory |
http://support.apple.com/kb/HT3969 | patch vendor advisory |
http://lists.apple.com/archives/security-announce/2009/Dec/msg00000.html | patch vendor advisory |
http://www.securityfocus.com/bid/37206 | vdb entry patch |
http://lists.apple.com/archives/security-announce/2009/Dec/msg00001.html | patch vendor advisory |
http://secunia.com/advisories/37581 | third party advisory vendor advisory |