VulnerabilityModified
CVE-2004-0925
Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.
MEDIUM 5.0EPSS 1.11%
Does this matter?
Lower severity and a low EPSS score (1.11%). Track it; it rarely justifies an emergency change on its own.
Description
Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 1.11% probability · 64th percentile
- CISA KEV
- Not listed
- Affected
- apple/mac os x · apple/mac os x server
- Source
- cve@mitre.org
References
- http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.htmlPatch, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.htmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.