Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authentication if the CRAM-MD5 hashed login fails, which could allow remote attackers to gain privileges by sniffing the password.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2003-10-30T05:00:00

Updated: 2024-08-08T02:05:12.647Z

Reserved: 2003-10-24T00:00:00

Link: CVE-2003-0881

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2003-11-03T05:00:00.000

Modified: 2008-09-05T20:35:30.327

Link: CVE-2003-0881

cve-icon Redhat

No data.