Description
Apple Mail.app 3.5 on Mac OS X, when "Store draft messages on the server" is enabled, stores draft copies of S/MIME email in plaintext on the email server, which allows server owners and remote man-in-the-middle attackers to read sensitive mail.
Affected products
- Apple / mail3.5 – 3.5
References
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/45688
- VENDOR_ADVISORYhttp://resources.enablesecurity.com/advisories/apple-mailapp-smime.txt
- MISChttp://www.securityfocus.com/bid/31598
- MISChttp://www.securityfocus.com/archive/1/497057/100/0/threaded
- MISChttp://enablesecurity.com/2008/10/03/apple-mailapp-security-advisory/
- MISChttp://securityreason.com/securityalert/4363
- MISChttp://www.securitytracker.com/id?1021019