Sploitus

CVE-2009-1723

1 known exploit for CVE-2009-1723

CFNetwork in Apple Mac OS X 10.5 before 10.5.8 places an incorrect URL in a certificate warning in certain 302 redirection scenarios, which makes it easier for remote attackers to trick a user into visiting an arbitrary https web site by leveraging an open redirect vulnerability, a different issue than CVE-2009-2062.

Affected products
Cfnetwork, Macos X
Apple Mac Os X
= 10.5.6, 10.5, 10.5.0, 10.5.1, 10.5.2, 10.5.3, 10.5.4, 10.5.5, 10.5.7
Apple Mac Os X Server
= 10.5, 10.5.0, 10.5.1, 10.5.2, 10.5.3, 10.5.4, 10.5.5, 10.5.6, 10.5.7
CVSS 2.0
4.3 MEDIUM
EPSS
1.4% (70th percentile)
NVD status
Modified
Published
2009-08-06
CVE-2009-1723 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2009-1723

Proof-of-concept code and exploit modules indexed by Sploitus