CVE-2005-0127: Medium severity Apple Mac OS X Server vulnerability
Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0127?
CVE-2005-0127 is classified as a moderate severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2005-0127?
To fix CVE-2005-0127, upgrade to a newer version of Mac OS X that does not generate Message-ID headers including Ethernet hardware information.
What systems are affected by CVE-2005-0127?
CVE-2005-0127 affects Mac OS X 10.3.7 and Mac OS X Server 10.3.7.
What type of attack does CVE-2005-0127 facilitate?
CVE-2005-0127 facilitates a potential privacy issue where remote attackers can link email messages to a specific machine.
Is there a workaround for CVE-2005-0127?
There are no known workarounds for CVE-2005-0127, so upgrading the system is the recommended approach.