CVE Published: 24/06/2011 |
CVE Updated: 06/08/2024 |
CVE Year: 2011 Source: apple |
Vendor: n/a |
Product: n/a Status : PUBLISHED
CVE-2011-0199 Description
The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a revoked certificate.