The Dictionary app in Apple OS X before 10.10.5 does not use HTTPS, which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network or spoof word definitions by modifying the client-server data stream.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/76340 | vdb entry |
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html | vendor advisory |
https://support.apple.com/kb/HT205031 | vendor advisory |
http://www.securitytracker.com/id/1033276 | vdb entry |