
一方で、こういう goto が原因で CVE-2014-1266 みたいな脆弱性が生まれたのも事実だし、あの時はダイクストラ先生が草葉の陰で大声出して笑っていただろうな
Post summary
The post merely references CVE-2014-1266 without providing any additional details or actionable information.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The SSLVerifySignedServerKeyExchange function in libsecurity_ssl/lib/sslKeyExchange.c in the Secure Transport feature in the Data Security component in Apple iOS 6.x before 6.1.6 and 7.x before 7.0.6, Apple TV 6.x before 6.0.2, and Apple OS X 10.9.x before 10.9.2 does not check the signature in a TLS Server Key Exchange message, which allows man-in-the-middle attackers to spoof SSL servers by (1) using an arbitrary private key for the signing step or (2) omitting the signing step.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
NONE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.

一方で、こういう goto が原因で CVE-2014-1266 みたいな脆弱性が生まれたのも事実だし、あの時はダイクストラ先生が草葉の陰で大声出して笑っていただろうな
Post summary
The post merely references CVE-2014-1266 without providing any additional details or actionable information.

@yutakakn2 CVE-2014-1266 gotofailバグ などでやっちゃった事例が検索できるようです。
Post summary
The tweet states that examples related to CVE-2014-1266’s gotofail bug can now be searched, but offers no further detail on the vulnerability or its exploitation.
3 of 3 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| OS | apple | iphone_os | - | - | - |
| OS | apple | mac_os_x | - | - | - |
| OS | apple | tvos | - | - | - |