CVE-2008-4491: Infoleak
Apple Mail.app 3.5 on Mac OS X, when "Store draft messages on the server" is enabled, stores draft copies of S/MIME email in plaintext on the email server, which allows server owners and remote man-in-the-middle attackers to read sensitive mail.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4491?
The severity of CVE-2008-4491 is classified as moderate, given the potential for sensitive information to be accessed by unauthorized parties.
How do I fix CVE-2008-4491?
To fix CVE-2008-4491, disable the option to 'Store draft messages on the server' in Apple Mail settings.
Which versions of Apple Mail are affected by CVE-2008-4491?
CVE-2008-4491 specifically affects Apple Mail version 3.5 on Mac OS X.
What kind of data is exposed in CVE-2008-4491?
CVE-2008-4491 exposes draft copies of S/MIME emails in plaintext, allowing unauthorized access to potentially sensitive information.
Can I still use Apple Mail if I am concerned about CVE-2008-4491?
Yes, you can still use Apple Mail safely by ensuring the 'Store draft messages on the server' option is turned off.