Mac OS X : OS X Server < 2.2.5 SSLv3 Information Disclosure (POODLE)
Medium Nessus Plugin ID 78599
The remote host is missing a security update for OS X Server.
The remote Mac OS X 10.8 host has a version of OS X Server installed that is prior to version 2.2.5. It is, therefore, affected by an information disclosure vulnerability. An error exists related to the way SSL 3.0 handles padding bytes when decrypting messages encrypted using block ciphers in cipher block chaining (CBC) mode. A man-in-the-middle attacker can decrypt a selected byte of a cipher text in as few as 256 tries if they are able to force a victim application to repeatedly send the same data over newly created SSL 3.0 connections. This is also known as the 'POODLE' issue.
Upgrade to Mac OS X Server version 2.2.5 or later.