CVE-2004-1088: High severity Apple Darwin Streaming Server vulnerability
Published Dec 2, 2004
·Updated
Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authentication information.
Affected Software
35 affected components
Apple Darwin Streaming Server=4.1.3
Apple Darwin Streaming Server=5.0.1
Apple Quicktime Streaming Server=4.1.1
Apple iOS and macOS=10.2
Apple iOS and macOS=10.2.1
Apple iOS and macOS=10.2.2
Apple iOS and macOS=10.2.3
Apple iOS and macOS=10.2.4
Apple iOS and macOS=10.2.5
Apple iOS and macOS=10.2.6
Apple iOS and macOS=10.2.7
Apple iOS and macOS=10.2.8
Apple iOS and macOS=10.3
Apple iOS and macOS=10.3.1
Apple iOS and macOS=10.3.2
Apple iOS and macOS=10.3.3
Apple iOS and macOS=10.3.4
Apple iOS and macOS=10.3.5
Apple iOS and macOS=10.3.6
Apple Mac OS X Server=10.2
Apple Mac OS X Server=10.2.1
Apple Mac OS X Server=10.2.2
Apple Mac OS X Server=10.2.3
Apple Mac OS X Server=10.2.4
Apple Mac OS X Server=10.2.5
Apple Mac OS X Server=10.2.6
Apple Mac OS X Server=10.2.7
Apple Mac OS X Server=10.2.8
Apple Mac OS X Server=10.3
Apple Mac OS X Server=10.3.1
Apple Mac OS X Server=10.3.2
Apple Mac OS X Server=10.3.3
Apple Mac OS X Server=10.3.4
Apple Mac OS X Server=10.3.5
Apple Mac OS X Server=10.3.6
Remediation
Patch Available
Patch Available
Event History
Dec 2, 2004
CVE Published
05:00 AM
Apr 14, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1088?
CVE-2004-1088 is considered a high severity vulnerability due to its potential to allow unauthorized email sending.
2
How do I fix CVE-2004-1088?
To fix CVE-2004-1088, you should update to the latest version of Postfix that addresses this vulnerability.
3
Which systems are affected by CVE-2004-1088?
CVE-2004-1088 affects various versions of Apple Mac OS X and its server software.
4
What type of attack does CVE-2004-1088 enable?
CVE-2004-1088 enables remote attackers to replay authentication information, allowing them to send emails without proper authentication.
5
Is there a workaround for CVE-2004-1088?
A temporary workaround for CVE-2004-1088 may involve disabling CRAM-MD5 authentication until the vulnerability can be patched.