Summary
libcurl-using applications can request a client certificate for transfer using the `CURLOPT_SSLCERT` option. When using the macOS native TLS library Secure Transport, applications can request the certificate by name or file name. Malicious users can create a file name with the same name, causing libcurl to send the wrong client certificate in the TLS connection handshake.
Products Potentially Affected
OS/Product |
Exposure |
XIQ-SE |
No |
|
Repair Recommendations
None.
Please see the full security advisory article here for more details and updates.