Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think that's not related to the SSL/TLS bug, but instead to the curl problem that also came with the update to 10.9.2. This is the description from Apple's security mailing list:

"curl Available for: OS X Mavericks 10.9 and 10.9.1 Impact: An attacker with a privileged network position may intercept user credentials or other sensitive information Description: When using curl to connect to an HTTPS URL containing an IP address, the IP address was not validated against the certificate. This issue does not affect systems prior to OS X Mavericks v10.9. CVE-ID CVE-2014-1263 : Roland Moriz of Moriz GmbH"



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: