PT-2005-2501 · Apple · Mail.App+1

Markus Wörle

·

Publicado

2005-05-11

·

Atualizado

2017-07-11

·

CVE-2005-1505

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mail.app version 2.0 in Mac OS 10.4
Description The issue concerns the new account wizard in Mail.app. When configuring an IMAP mail account and checking the credentials, it does not prompt the user to use SSL until after the password has already been sent. This results in the password being sent in plaintext.
Recommendations For Mail.app version 2.0 in Mac OS 10.4, consider configuring the IMAP account manually to ensure SSL is used from the start, thus preventing the password from being sent in plaintext. As a temporary workaround, avoid using the new account wizard for IMAP configurations until a fix is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-1505

Produtos afetados

Apple Macos
Mail.App