Security Advisory
CVE-2011-3444
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.