The SecKeyDeriveFromPassword function in Apple OS X before 10.12 does not use the CF_RETURNS_RETAINED keyword, which allows attackers to obtain sensitive information from process memory by triggering key derivation.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1036858 | vdb entry |
http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.html | vendor advisory mailing list |
http://www.securityfocus.com/bid/93055 | vdb entry |
https://support.apple.com/HT207170 | vendor advisory |