Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates, which allows remote attackers to obtain sensitive information by sniffing the network.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://support.apple.com/HT204659 | vendor advisory |
http://www.securityfocus.com/bid/73982 | exploit vdb entry third party advisory |
http://www.securitytracker.com/id/1032048 | vdb entry third party advisory |
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html | vendor advisory |