Apple Mac OS X 10.5 Postfix Security Bypass Vulnerability
BID:31721
Info
Apple Mac OS X 10.5 Postfix Security Bypass Vulnerability
| Bugtraq ID: | 31721 |
| Class: | Design Error |
| CVE: |
CVE-2008-3646 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2008 12:00AM |
| Updated: | Oct 15 2008 04:47PM |
| Credit: | Pelle Johansson |
| Vulnerable: |
Apple Mac OS X 10.5 |
| Not Vulnerable: | |
Discussion
Apple Mac OS X 10.5 Postfix Security Bypass Vulnerability
Apple Mac OS X Postfix is prone to a security-bypass vulnerability.
Attackers may be able to send email to local users and otherwise make use of the SMTP protocol.
This issue affects Mac OS X v10.5.
NOTE: This issue was previously covered in BID 31681 (Apple Mac OS X 2008-007 Multiple Security Vulnerabilities) but has been given its own record to better document the vulnerability.
Apple Mac OS X Postfix is prone to a security-bypass vulnerability.
Attackers may be able to send email to local users and otherwise make use of the SMTP protocol.
This issue affects Mac OS X v10.5.
NOTE: This issue was previously covered in BID 31681 (Apple Mac OS X 2008-007 Multiple Security Vulnerabilities) but has been given its own record to better document the vulnerability.
Exploit / POC
Apple Mac OS X 10.5 Postfix Security Bypass Vulnerability
An attacker may exploit this issue using commonly available network tools.
An attacker may exploit this issue using commonly available network tools.
Solution / Fix
Apple Mac OS X 10.5 Postfix Security Bypass Vulnerability
Solution:
The vendor has released fixes; please see the references for more information.
Solution:
The vendor has released fixes; please see the references for more information.
References
Apple Mac OS X 10.5 Postfix Security Bypass Vulnerability
References:
References: