First published: Sat Jan 29 2005(Updated: )
Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X Server | =10.3.7 | |
macOS Yosemite | =10.3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0127 is classified as a moderate severity vulnerability due to its potential for information disclosure.
To fix CVE-2005-0127, upgrade to a newer version of Mac OS X that does not generate Message-ID headers including Ethernet hardware information.
CVE-2005-0127 affects Mac OS X 10.3.7 and Mac OS X Server 10.3.7.
CVE-2005-0127 facilitates a potential privacy issue where remote attackers can link email messages to a specific machine.
There are no known workarounds for CVE-2005-0127, so upgrading the system is the recommended approach.