CVE-2009-0161Improper Input Validation in Apple MAC OS X

Severity
6.4MEDIUMNVD
EPSS
0.3%
top 51.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13
Latest updateMay 2

Description

The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified invalid response as a successful OCSP certificate validation, which might allow remote attackers to spoof certificate authentication via a revoked certificate.

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages2 packages

NVDapple/mac_os_x7 versions+6
NVDapple/mac_os_x_server7 versions+6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7c3q-2h3j-w943: The OpenSSL::OCSP module for Ruby in Apple Mac OS X 102022-05-02
CVEList
CVE-2009-0161: The OpenSSL::OCSP module for Ruby in Apple Mac OS X 102009-05-13

📋Vendor Advisories

1
Red Hat
kernel: tty->pgrp races2009-12-17

📐Framework References

1
CWE
Improper Check for Certificate Revocation
CVE-2009-0161 — Improper Input Validation in Apple | cvebase