The default configuration of Mail.app in Mac OS X 10.0 through 10.0.4 and 10.1 through 10.1.5 sends iDisk authentication credentials in cleartext when connecting to Mac.com, which could allow remote attackers to obtain passwords by sniffing network traffic.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mac_os_x | Apple | 10.0 (including) | 10.0 (including) |
Mac_os_x | Apple | 10.0.1 (including) | 10.0.1 (including) |
Mac_os_x | Apple | 10.0.2 (including) | 10.0.2 (including) |
Mac_os_x | Apple | 10.0.3 (including) | 10.0.3 (including) |
Mac_os_x | Apple | 10.0.4 (including) | 10.0.4 (including) |
Mac_os_x | Apple | 10.1 (including) | 10.1 (including) |
Mac_os_x | Apple | 10.1.1 (including) | 10.1.1 (including) |
Mac_os_x | Apple | 10.1.2 (including) | 10.1.2 (including) |
Mac_os_x | Apple | 10.1.3 (including) | 10.1.3 (including) |
Mac_os_x | Apple | 10.1.4 (including) | 10.1.4 (including) |
Mac_os_x | Apple | 10.1.5 (including) | 10.1.5 (including) |