Apple Mail EMail Message ID Header Information Disclosure Vulnerability
BID:12366
Info
Apple Mail EMail Message ID Header Information Disclosure Vulnerability
| Bugtraq ID: | 12366 |
| Class: | Design Error |
| CVE: |
CVE-2005-0127 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 26 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | Carl Purvis is credited with the discovery of this issue. |
| Vulnerable: |
Apple Mail |
| Not Vulnerable: |
Apple Mac OS X Server 10.3.8 Apple Mac OS X 10.3.8 |
Discussion
Apple Mail EMail Message ID Header Information Disclosure Vulnerability
An information disclosure vulnerability affects the email message ID generation of Apple Mail. This issue is due to a design error that causes the application to insecurely generate email message IDs.
An attacker may leverage this issue to identify the specific computer that an email has been sent from, other attacks may also be possible.
An information disclosure vulnerability affects the email message ID generation of Apple Mail. This issue is due to a design error that causes the application to insecurely generate email message IDs.
An attacker may leverage this issue to identify the specific computer that an email has been sent from, other attacks may also be possible.
Exploit / POC
Apple Mail EMail Message ID Header Information Disclosure Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Apple Mail EMail Message ID Header Information Disclosure Vulnerability
Solution:
Apple Computers has released advisory APPLE-SA-2005-01-25 along with a security update dealing with this and other issues. Please see the referenced advisory for more information.
Apple Computers has released Mac OS X version 10.3.8 dealing with this issue. This upgrade includes the security patches shipped with the referenced security update.
Solution:
Apple Computers has released advisory APPLE-SA-2005-01-25 along with a security update dealing with this and other issues. Please see the referenced advisory for more information.
Apple Computers has released Mac OS X version 10.3.8 dealing with this issue. This upgrade includes the security patches shipped with the referenced security update.
References
Apple Mail EMail Message ID Header Information Disclosure Vulnerability
References:
References:
- Apple Mail Home Page (Apple)