CVE-2005-1505: High severity Apple Mail vulnerability
The new account wizard in Mail.app 2.0 in Mac OS 10.4, when configuring an IMAP mail account and checking the credentials, does not prompt the user to use SSL until after the password has already been sent, which causes the password to be sent in plaintext.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1505?
CVE-2005-1505 is considered a medium severity vulnerability due to the potential exposure of user credentials.
How do I fix CVE-2005-1505?
To fix CVE-2005-1505, ensure that SSL is enabled for IMAP credentials before sending your password.
What types of systems are affected by CVE-2005-1505?
CVE-2005-1505 affects Apple Mail 2.0 on Mac OS 10.4 when configuring IMAP mail accounts.
What kind of data is compromised in CVE-2005-1505?
CVE-2005-1505 allows passwords to be sent in plaintext, which could be intercepted by attackers.
Is CVE-2005-1505 still relevant today?
CVE-2005-1505 is less relevant today due to advances in email security protocols, but users should still be aware of legacy systems that may not be updated.