Unrated severityNVD Advisory· Published Jan 27, 2005· Updated Jun 16, 2026
CVE-2004-0925
CVE-2004-0925
Description
Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.
Affected products
13cpe:2.3:o:apple:mac_os_x:10.3:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:o:apple:mac_os_x:10.3:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.3.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.3.2:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.3.3:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.3.4:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.3.5:*:*:*:*:*:*:*
- (no CPE)range: <=10.3.5
cpe:2.3:o:apple:mac_os_x_server:10.3:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:o:apple:mac_os_x_server:10.3:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x_server:10.3.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x_server:10.3.2:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x_server:10.3.3:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x_server:10.3.4:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x_server:10.3.5:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- lists.apple.com/archives/security-announce/2004/Oct/msg00000.htmlnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.