PT-2003-1935 · Apple · Mail+1

Publicado

2003-10-30

·

Atualizado

2008-09-05

·

CVE-2003-0881

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mac OS X versions prior to 10.3
Description The issue concerns the Mail application in Mac OS X, which, when configured to use MD5 Challenge Response, falls back to plaintext authentication if the CRAM-MD5 hashed login fails. This could allow remote attackers to gain privileges by sniffing the password.
Recommendations For versions prior to 10.3, consider updating to version 10.3 or later to resolve the issue. As a temporary workaround, avoid using the MD5 Challenge Response configuration in the Mail application until a patch is available. Restrict access to sensitive networks to minimize the risk of password sniffing.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0881

Produtos afetados

Macos X
Mail