Apple Mac OS X Ethernet address disclosure
| macos-ethernet-address-disclosure (19085) |
Description:
Apple Mac OS X and Mac OS X Server could allow a remote attacker to obtain sensitive information. Mail in Mac OS determines Message-ID headers for outgoing emails using the globally unique Ethernet MAC address. If a remote attacker is able to receive or monitor the email messages, the attacker could then determine the Ethernet address of the victim.
Platforms Affected:
- Apple, Mac OS X 10.3.7
- Apple, Mac OS X Server 10.3.7
Remedy:
Apply Security Update 2005-001, available from the Apple Downloads Web page. See References.
Consequences:
Obtain Information
References:
- Apple Downloads Web page, Apple Downloads at http://www.apple.com/support/downloads/.
- AppleCare Knowledge Base Document 300770, Apple Security Update 2005-001 at http://docs.info.apple.com/article.html?artnum=300770.
- CIAC Information Bulletin P-116, Apple Security Update 2005-001 for Mac OS X at http://www.ciac.org/ciac/bulletins/p-116.shtml.
- Mac OS X Server Web page, Mac OS X Server at http://www.apple.com/server/macosx/.
- Mac OS X Web page, Apple - Mac OS X at http://www.apple.com/macosx/.
- BID-12366: Apple Mail EMail Message ID Header Information Disclosure Vulnerability
- CVE-2005-0127: Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine.
- SA14005: Mac OS X Security Update Fixes Multiple Vulnerabilities
- SECTRACK ID: 1013001: Mac OS X Mail Discloses Ethernet Address to Remote Users
- US-CERT VU#464662: Apple Mac OS X vulnerable to information disclosure in Message-ID header
Reported:
Jan 26, 2005
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
