CVE-2008-4491 Information

Description

Apple Mail.app 3.5 on Mac OS X when \Store draft messages on the server\ is enabled stores draft copies of S/MIME email in plaintext on the email server which allows server owners and remote man-in-the-middle attackers to read sensitive mail.

Reference

http://enablesecurity.com/2008/10/03/apple-mailapp-security-advisory/ http://resources.enablesecurity.com/advisories/apple-mailapp-smime.txt http://securityreason.com/securityalert/4363 http://www.securityfocus.com/archive/1/497057/100/0/threaded http://www.securityfocus.com/bid/31598 http://www.securitytracker.com/id?1021019 https://exchange.xforce.ibmcloud.com/vulnerabilities/45688

Share on: