PT-2003-1935 · Apple · Mail+1
Publicado
2003-10-30
·
Atualizado
2008-09-05
·
CVE-2003-0881
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Mac OS X versions prior to 10.3
Description
The issue concerns the Mail application in Mac OS X, which, when configured to use MD5 Challenge Response, falls back to plaintext authentication if the CRAM-MD5 hashed login fails. This could allow remote attackers to gain privileges by sniffing the password.
Recommendations
For versions prior to 10.3, consider updating to version 10.3 or later to resolve the issue. As a temporary workaround, avoid using the MD5 Challenge Response configuration in the Mail application until a patch is available. Restrict access to sensitive networks to minimize the risk of password sniffing.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Macos X
Mail