CVE-2008-1580

Description

CFNetwork in Safari in Apple Mac OS X before 10.5.3 automatically sends an SSL client certificate in response to a web servers certificate request, which allows remote web sites to obtain sensitive information (Subject data) from personally identifiable certificates, and use arbitrary certificates to track user activities across domains, a related issue to CVE-2007-4879.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.19

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Apple Safari 3.1Windows
Multiple Vulnerabilities are affected in Apple Safari 2.3Windows
Multiple Vulnerabilities are affected in Apple Safari for MAC 26.1Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-613034Apple Safari for MAC (MacOS Sequoia) (26.2)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234