CVE-2015-5884: Infoleak
The Mail Drop feature in Mail in Apple OS X before 10.11 mishandles encryption parameters for attachments, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during transmission of an S/MIME e-mail message with a large attachment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5884?
CVE-2015-5884 is rated as a moderate severity vulnerability affecting the Mail Drop feature in OS X.
How do I fix CVE-2015-5884?
To mitigate CVE-2015-5884, it is recommended to upgrade to OS X 10.11 or later, which addresses the vulnerability.
What does CVE-2015-5884 affect?
CVE-2015-5884 affects the Mail Drop feature in Apple OS X versions prior to 10.11.
What type of attack is possible with CVE-2015-5884?
CVE-2015-5884 allows remote attackers to potentially obtain sensitive information by intercepting S/MIME email messages with large attachments.
Is my version of OS X vulnerable to CVE-2015-5884?
If you are using OS X versions prior to 10.11, your system is vulnerable to CVE-2015-5884.