Required CVE Record Information
Description
Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple TV before 6.1.1 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack."
References 4 Total
- archives.neohapsis.com: APPLE-SA-2014-04-22-1 vendor-advisory
- archives.neohapsis.com: APPLE-SA-2014-04-22-2 vendor-advisory
- archives.neohapsis.com: APPLE-SA-2014-04-22-3 vendor-advisory
- https://secure-resumption.com/
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- archives.neohapsis.com: APPLE-SA-2014-04-22-1 vendor-advisoryx_transferred
- archives.neohapsis.com: APPLE-SA-2014-04-22-2 vendor-advisoryx_transferred
- archives.neohapsis.com: APPLE-SA-2014-04-22-3 vendor-advisoryx_transferred
- https://secure-resumption.com/ x_transferred