Apple Security Advisory 2013-09-18-3
Posted by deepcore on September 19, 2013 – 2:01 am
Apple Security Advisory 2013-09-18-3 – Xcode 5.0 is now available and addresses a security issue in Git. When using the imap-send command, git did not verify that the server hostname matched a domain name in the X.509 certificate, which allowed a man-in-the-middle attacker to spoof SSL servers via an arbitrary valid certificate. This issue was addressed by updating git to version 1.8.3.1.
Continued here:
Apple Security Advisory 2013-09-18-3
Post a reply
You must be logged in to post a comment.