PT-2004-2064 · Apple · Macos X+1

Published

2004-12-02

·

Updated

2017-07-11

·

CVE-2004-1088

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Postfix server for Apple Mac OS X version 10.3.6
Description: The issue allows remote attackers to send mail without authentication by replaying authentication information when using CRAM-MD5.
Recommendations: For Postfix server for Apple Mac OS X version 10.3.6, consider disabling the use of CRAM-MD5 authentication until a patch is available. Restrict access to the mail server to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1088

Affected Products

Macos X
Postfix