Description
The SecKeyDeriveFromPassword function in Apple OS X before 10.12 does not use the CF_RETURNS_RETAINED keyword, which allows attackers to obtain sensitive information from process memory by triggering key derivation.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-5737 | The SecKeyDeriveFromPassword function in Apple OS X before 10.12 does not use the CF_RETURNS_RETAINED keyword, which allows attackers to obtain sensitive information from process memory by triggering key derivation. |
References
History
No history.
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2024-08-06T00:39:26.070Z
Reserved: 2016-05-11T00:00:00.000Z
Link: CVE-2016-4752
No data.
Status : Modified
Published: 2016-09-25T10:59:48.970
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-4752
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD