First published: Thu Oct 28 2004(Updated: )
Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X Server | =10.3.2 | |
Apple Mac OS X Server | =10.3.5 | |
macOS Yosemite | =10.3.1 | |
macOS Yosemite | =10.3.5 | |
Apple Mac OS X Server | =10.3.3 | |
Apple Mac OS X Server | =10.3.4 | |
macOS Yosemite | =10.3.2 | |
Apple Mac OS X Server | =10.3 | |
Apple Mac OS X Server | =10.3.1 | |
macOS Yosemite | =10.3.4 | |
macOS Yosemite | =10.3.3 | |
macOS Yosemite | =10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0925 is considered a moderate severity vulnerability as it can prevent legitimate users from authenticating.
To fix CVE-2004-0925, upgrade Postfix on affected Mac OS X versions to a version where this issue is resolved.
CVE-2004-0925 affects Mac OS X 10.3.x versions from 10.3.1 to 10.3.5 with SMTPD AUTH enabled.
CVE-2004-0925 is an authentication bypass vulnerability that affects the Postfix mail server.
Users of Mac OS X who rely on SMTPD AUTH for mail services are impacted by CVE-2004-0925.