Vulnerability Name: | CVE-2004-0925 (CCN-17595) | ||||||||
Assigned: | 2004-10-05 | ||||||||
Published: | 2004-10-05 | ||||||||
Updated: | 2008-09-10 | ||||||||
Summary: | Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2004-0925 Source: CCN Type: AppleCare Knowledge Base Document 61798 Apple Security Update 2004-09-30 Source: APPLE Type: Patch, Vendor Advisory APPLE-SA-2004-09-30 Source: CCN Type: CIAC Information Bulletin P-002 Apple Security Update Source: CCN Type: OSVDB ID: 10500 Apple Mac OS X Postfix SMTPD AUTH Username Overflow DoS Source: CCN Type: BID-11323 Apple Mac OS X Postfix Release SMTPD AUTH Username Denial Of Service Vulnerability Source: XF Type: UNKNOWN macos-postfix-smtpd-dos(17595) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |