Vulnerable Systems:
* Apple OS X Lion v10.7.4 curl
There are known attacks on the confidentiality of SSL 3.0 and TLS 1.0 when a cipher suite uses a block cipher in CBC mode. curl disabled the 'empty fragment' countermeasure which prevented these attacks. This issue is addressed by enabling empty fragments.
Vendor Status:
Apple had issued an update for this vulnerability