CVE Vulnerabilities

CVE-2012-3698

Published: Jul 26, 2012 | Modified: Jul 31, 2012
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Apple Xcode before 4.4 does not properly compose a designated requirement (DR) during signing of programs that lack bundle identifiers, which allows remote attackers to read keychain entries via a crafted app, as demonstrated by the keychain entries of a (1) helper tool or (2) command-line tool.

Affected Software

Name Vendor Start Version End Version
Xcode Apple * 4.3.3 (including)
Xcode Apple 1.5.0 (including) 1.5.0 (including)
Xcode Apple 2.0.0 (including) 2.0.0 (including)
Xcode Apple 2.1.0 (including) 2.1.0 (including)
Xcode Apple 2.2.0 (including) 2.2.0 (including)
Xcode Apple 2.3.0 (including) 2.3.0 (including)
Xcode Apple 2.4.0 (including) 2.4.0 (including)
Xcode Apple 2.4.1 (including) 2.4.1 (including)
Xcode Apple 3.1 (including) 3.1 (including)
Xcode Apple 3.1.1 (including) 3.1.1 (including)
Xcode Apple 3.1.2 (including) 3.1.2 (including)
Xcode Apple 3.1.3 (including) 3.1.3 (including)
Xcode Apple 3.1.4 (including) 3.1.4 (including)
Xcode Apple 3.2.1 (including) 3.2.1 (including)
Xcode Apple 3.2.2 (including) 3.2.2 (including)
Xcode Apple 3.2.3 (including) 3.2.3 (including)
Xcode Apple 3.2.4 (including) 3.2.4 (including)
Xcode Apple 3.2.5 (including) 3.2.5 (including)
Xcode Apple 4.0 (including) 4.0 (including)
Xcode Apple 4.0.1 (including) 4.0.1 (including)
Xcode Apple 4.0.2 (including) 4.0.2 (including)
Xcode Apple 4.1.1 (including) 4.1.1 (including)
Xcode Apple 4.2 (including) 4.2 (including)
Xcode Apple 4.2.1 (including) 4.2.1 (including)
Xcode Apple 4.3 (including) 4.3 (including)
Xcode Apple 4.3.1 (including) 4.3.1 (including)
Xcode Apple 4.3.2 (including) 4.3.2 (including)

References