ID

VAR-201008-0310


CVE

CVE-2010-1802


TITLE

Apple Mac OS X of libsecurity In SSL Vulnerability impersonating a server

Trust: 0.8

sources: JVNDB: JVNDB-2010-001973

DESCRIPTION

libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name strings in X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a certificate associated with a similar domain name, as demonstrated by use of a www.example.con certificate to spoof www.example.com. Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks. This issue affects the following: Mac OS X 10.5.8 and 10.6.4 Mac OS X Server 10.5.8 and 10.6.4

Trust: 1.98

sources: NVD: CVE-2010-1802 // JVNDB: JVNDB-2010-001973 // BID: 42655 // VULHUB: VHN-44407

AFFECTED PRODUCTS

vendor:applemodel:libsecurityscope: - version: -

Trust: 1.4

vendor:applemodel:libsecurityscope:eqversion:*

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.6.4

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.5.8

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.5.8

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.6.4

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:v10.5.8

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:v10.6.4

Trust: 0.8

vendor:applemodel:mac os x serverscope:eqversion:v10.5.8

Trust: 0.8

vendor:applemodel:mac os x serverscope:eqversion:v10.6.4

Trust: 0.8

vendor:applemodel:mac osscope:eqversion:x10.6

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.6

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.6.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.6

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.3

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.6.1

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.6

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.3

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.8

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.8

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.5

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.6.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.7

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.4

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.6.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.1

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.7

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.2

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.6.4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.6.3

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.6.4

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.6.3

Trust: 0.3

sources: BID: 42655 // JVNDB: JVNDB-2010-001973 // CNNVD: CNNVD-201008-295 // NVD: CVE-2010-1802

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2010-1802
value: MEDIUM

Trust: 1.0

NVD: CVE-2010-1802
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201008-295
value: MEDIUM

Trust: 0.6

VULHUB: VHN-44407
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2010-1802
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-44407
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-44407 // JVNDB: JVNDB-2010-001973 // CNNVD: CNNVD-201008-295 // NVD: CVE-2010-1802

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.9

sources: VULHUB: VHN-44407 // JVNDB: JVNDB-2010-001973 // NVD: CVE-2010-1802

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201008-295

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201008-295

CONFIGURATIONS

sources: JVNDB: JVNDB-2010-001973

PATCH

title:HT4312url:http://support.apple.com/kb/HT4312

Trust: 0.8

title:HT4312url:http://support.apple.com/kb/HT4312?viewlocale=ja_JP

Trust: 0.8

sources: JVNDB: JVNDB-2010-001973

EXTERNAL IDS

db:NVDid:CVE-2010-1802

Trust: 2.8

db:SECTRACKid:1024359

Trust: 2.5

db:JVNDBid:JVNDB-2010-001973

Trust: 0.8

db:CNNVDid:CNNVD-201008-295

Trust: 0.7

db:APPLEid:APPLE-SA-2010-08-24-1

Trust: 0.6

db:BIDid:42655

Trust: 0.4

db:VULHUBid:VHN-44407

Trust: 0.1

sources: VULHUB: VHN-44407 // BID: 42655 // JVNDB: JVNDB-2010-001973 // CNNVD: CNNVD-201008-295 // NVD: CVE-2010-1802

REFERENCES

url:http://securitytracker.com/id?1024359

Trust: 2.5

url:http://lists.apple.com/archives/security-announce/2010//aug/msg00003.html

Trust: 1.7

url:http://support.apple.com/kb/ht4312

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2010-1802

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2010-1802

Trust: 0.8

url:http://www.apple.com/macosx/

Trust: 0.3

sources: VULHUB: VHN-44407 // BID: 42655 // JVNDB: JVNDB-2010-001973 // CNNVD: CNNVD-201008-295 // NVD: CVE-2010-1802

CREDITS

Peter Speck

Trust: 0.3

sources: BID: 42655

SOURCES

db:VULHUBid:VHN-44407
db:BIDid:42655
db:JVNDBid:JVNDB-2010-001973
db:CNNVDid:CNNVD-201008-295
db:NVDid:CVE-2010-1802

LAST UPDATE DATE

2025-04-11T22:56:37.248000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-44407date:2010-08-26T00:00:00
db:BIDid:42655date:2010-08-24T00:00:00
db:JVNDBid:JVNDB-2010-001973date:2010-09-08T00:00:00
db:CNNVDid:CNNVD-201008-295date:2010-09-03T00:00:00
db:NVDid:CVE-2010-1802date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULHUBid:VHN-44407date:2010-08-25T00:00:00
db:BIDid:42655date:2010-08-24T00:00:00
db:JVNDBid:JVNDB-2010-001973date:2010-09-08T00:00:00
db:CNNVDid:CNNVD-201008-295date:2010-08-27T00:00:00
db:NVDid:CVE-2010-1802date:2010-08-25T20:00:16.797