First published: Thu Oct 28 2004(Updated: )
Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Server | =10.3.2 | |
Apple macOS Server | =10.3.5 | |
Apple iOS and macOS | =10.3.1 | |
Apple iOS and macOS | =10.3.5 | |
Apple macOS Server | =10.3.3 | |
Apple macOS Server | =10.3.4 | |
Apple iOS and macOS | =10.3.2 | |
Apple macOS Server | =10.3 | |
Apple macOS Server | =10.3.1 | |
Apple iOS and macOS | =10.3.4 | |
Apple iOS and macOS | =10.3.3 | |
Apple iOS and macOS | =10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0925 is considered a moderate severity vulnerability as it can prevent legitimate users from authenticating.
To fix CVE-2004-0925, upgrade Postfix on affected Mac OS X versions to a version where this issue is resolved.
CVE-2004-0925 affects Mac OS X 10.3.x versions from 10.3.1 to 10.3.5 with SMTPD AUTH enabled.
CVE-2004-0925 is an authentication bypass vulnerability that affects the Postfix mail server.
Users of Mac OS X who rely on SMTPD AUTH for mail services are impacted by CVE-2004-0925.