The MCX Desktop Config Profiles implementation in Apple OS X before 10.10 retains web-proxy settings from uninstalled mobile-configuration profiles, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging access to an unintended proxy server.
Weaknesses in this category are typically introduced during the configuration of the software.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/97628 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html | vendor advisory broken link |
http://www.securitytracker.com/id/1031063 | third party advisory vdb entry |
http://www.securityfocus.com/bid/70631 | third party advisory vdb entry |
https://support.apple.com/kb/HT6535 | vendor advisory |