Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The SecKeyDeriveFromPassword function in Apple OS X before 10.12 does not use the CF_RETURNS_RETAINED keyword, which allows attackers to obtain sensitive information from process memory by triggering key derivation.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apple OS X 安全漏洞
Vulnerability Description
Apple OS X是美国苹果(Apple)公司为Mac计算机所开发的一套专用操作系统。 Apple OS X 10.12之前版本中的‘SecKeyDeriveFromPassword’函数存在安全漏洞,该漏洞源于程序没有使用CF_RETURNS_RETAINED关键字。攻击者可利用该漏洞获取进程内存中的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A