Required CVE Record Information
Description
The default configuration of Mail.app in Mac OS X 10.0 through 10.0.4 and 10.1 through 10.1.5 sends iDisk authentication credentials in cleartext when connecting to Mac.com, which could allow remote attackers to obtain passwords by sniffing network traffic.
References 4 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- archives.neohapsis.com: 20020724 Re: Apple OSX and iDisk and Mail.app mailing-listx_transferred
- iss.net: macos-idisk-insecure-password(9670) vdb-entryx_transferred
- archives.neohapsis.com: 20020724 Apple OSX and iDisk and Mail.app mailing-listx_transferred
- securityfocus.com: 5303 vdb-entryx_transferred