Security Advisory

CVE-2015-5920

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-09-18 10:00:00
Last updated 2024-08-06 07:06:34
Assigner apple
CVSS score not scored
State PUBLISHED

Description

The Software Update component in Apple iTunes before 12.3 does not properly handle redirection, which allows man-in-the-middle attackers to discover encrypted SMB credentials via unspecified vectors.