Apple Mail S/MIME Draft Message Encryption Weakness
BID:31598
Info
Apple Mail S/MIME Draft Message Encryption Weakness
| Bugtraq ID: | 31598 |
| Class: | Design Error |
| CVE: |
CVE-2008-4491 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 06 2008 12:00AM |
| Updated: | May 07 2015 05:22PM |
| Credit: | EnableSecurity |
| Vulnerable: |
Apple Mail 3.5 (929.4/929.2) Apple Mail |
| Not Vulnerable: | |
Discussion
Apple Mail S/MIME Draft Message Encryption Weakness
Apple Mail is prone to a weakness in its implementation of S/MIME encryption. An attacker with access to an IMAP or Exchange email server may be able to take advantage of this issue to obtain sensitive information.
Mail 3.5 (929.4/929.2) is vulnerable; other versions may also be affected.
Apple Mail is prone to a weakness in its implementation of S/MIME encryption. An attacker with access to an IMAP or Exchange email server may be able to take advantage of this issue to obtain sensitive information.
Mail 3.5 (929.4/929.2) is vulnerable; other versions may also be affected.
Exploit / POC
Apple Mail S/MIME Draft Message Encryption Weakness
An attacker may use readily available tools to take advantage of this weakness.
An attacker may use readily available tools to take advantage of this weakness.
Solution / Fix
Apple Mail S/MIME Draft Message Encryption Weakness
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Apple Mail S/MIME Draft Message Encryption Weakness
References:
References: