cbcvebase.
CVE-2011-3444
published 2012-02-02

CVE-2011-3444: Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote…

medium4.3CVSS 3.1
AVNACMAuNCPINAN
Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.

Affected

6 ranges
VendorProductVersion rangeFixed in
applemac_os_x<= 10.7.2
applemac_os_x
applemac_os_x
applemac_os_x_server<= 10.7.2
applemac_os_x_server
applemac_os_x_server