The Hash-based Message Authentication Code (HMAC) provider in Java on Apple Mac OS X 10.4.11, 10.5.4, and 10.5.5 uses an uninitialized variable, which allows remote attackers to execute arbitrary code via a crafted applet, related to an error checking issue.
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mac_os_x | Apple | 10.4.11 (including) | 10.4.11 (including) |
Mac_os_x | Apple | 10.5.4 (including) | 10.5.4 (including) |
Mac_os_x | Apple | 10.5.5 (including) | 10.5.5 (including) |
Mac_os_x_server | Apple | 10.4.11 (including) | 10.4.11 (including) |
Mac_os_x_server | Apple | 10.5.4 (including) | 10.5.4 (including) |
Mac_os_x_server | Apple | 10.5.5 (including) | 10.5.5 (including) |