CVE-2009-1723Apple MAC OS X vulnerability

4 documents4 sources
Severity
4.3MEDIUMNVD
EPSS
0.6%
top 30.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 6
Latest updateMay 2

Description

CFNetwork in Apple Mac OS X 10.5 before 10.5.8 places an incorrect URL in a certificate warning in certain 302 redirection scenarios, which makes it easier for remote attackers to trick a user into visiting an arbitrary https web site by leveraging an open redirect vulnerability, a different issue than CVE-2009-2062.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDapple/mac_os_x9 versions+8
NVDapple/mac_os_x_server9 versions+8

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j4q2-v3p9-r94x: CFNetwork in Apple Mac OS X 102022-05-02
CVEList
CVE-2009-1723: CFNetwork in Apple Mac OS X 102009-08-06

💥Exploits & PoCs

1
Exploit-DB
Siemens Gigaset SE361 WLAN - Remote Reboot (Denial of Service)2009-09-11
CVE-2009-1723 — Apple MAC OS X vulnerability | cvebase