Mail in Apple iOS before 8 does not prevent sending a LOGIN command to a LOGINDISABLED IMAP server, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Iphone_os | Apple | * | 7.1.2 (including) |
Iphone_os | Apple | 7.0 (including) | 7.0 (including) |
Iphone_os | Apple | 7.0.1 (including) | 7.0.1 (including) |
Iphone_os | Apple | 7.0.2 (including) | 7.0.2 (including) |
Iphone_os | Apple | 7.0.3 (including) | 7.0.3 (including) |
Iphone_os | Apple | 7.0.4 (including) | 7.0.4 (including) |
Iphone_os | Apple | 7.0.5 (including) | 7.0.5 (including) |
Iphone_os | Apple | 7.0.6 (including) | 7.0.6 (including) |
Iphone_os | Apple | 7.1 (including) | 7.1 (including) |
Iphone_os | Apple | 7.1.1 (including) | 7.1.1 (including) |