FTA:<p>Security - Secure Transport<p>Available for: OS X Mountain Lion v10.8.5, OS X Mavericks v10.9.2<p>Impact: An attacker with a privileged network position may capture<p>data or change the operations performed in sessions protected by SSL<p>Description: In a 'triple handshake' attack, it was possible for an
attacker to establish two connections which had the same encryption
keys and handshake, insert the attacker's data in one connection, and
renegotiate so that the connections may be forwarded to each other.<p>To prevent attacks based on this scenario, Secure Transport was
changed so that, by default, a renegotiation must present the same
server certificate as was presented in the original connection. This
issue does not affect Mac OS X 10.7 systems and earlier.<p>CVE-ID
CVE-2014-1295 : Antoine Delignat-Lavaud, Karthikeyan Bhargavan and
Alfredo Pironti of Prosecco at Inria Paris<p>That doesn't sound good…