Time Machine in Apple Mac OS X before 10.7.4 does not require continued use of SRP-based authentication after this authentication method is first used, which allows remote attackers to read Time Capsule credentials by spoofing the backup volume.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/53445 | vdb entry |
http://support.apple.com/kb/HT5281 | vendor advisory |
http://lists.apple.com/archives/security-announce/2012/May/msg00001.html | vendor advisory |