Release date:
Updated on:
Affected Systems:
Apple XCode 4.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54679
Cve id: CVE-2012-3698, CVE-2011-3389
Xcode is a development tool used on Apple machines.
Versions earlier than Apple Xcode 4.4 have security vulnerabilities. Malicious users can exploit this vulnerability to leak sensitive information, hijack user sessions, and bypass certain security restrictions.
1) there is a design error in the implementation of SSL 3.0 and TLS 1.0 protocols.
2) errors in DR implementation allow the App Store application to access the key chain project in the Helper tool built with Xcode.
<* Source: Apple
Link: http://support.apple.com/kb/HT5416
Http://secunia.com/advisories/50068/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apple
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://support.apple.com/