CVE-2004-0925Apple MAC OS X vulnerability

2 documents2 sources
Severity
5.0MEDIUMNVD
EPSS
0.5%
top 34.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 27
Latest updateApr 29

Description

Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDapple/mac_os_x6 versions+5
NVDapple/mac_os_x_server6 versions+5

Patches

🔴Vulnerability Details

1
GHSA
GHSA-fq92-p8q5-3756: Postfix on Mac OS X 102022-04-29
CVE-2004-0925 — Apple MAC OS X vulnerability | cvebase