CVE-2003-0881

Mail in Mac OS X <10.3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authentication if the CRAM-MD5 hashed login fails, which could allow remote attackers to gain privileges by sniffing the password.

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
http://docs.info.apple.com/article.html?artnum=61798

Scores

EPSS 0.0137
EPSS Percentile 69.1%

Details

Status published
Products (1)
apple/mac_os_x < 10.3
Published Nov 03, 2003
Tracked Since Feb 18, 2026