CVE Database
/

CVE-2011-0411

Back to search

CVE-2011-0411

Published: Mar 16, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.

VendorProductVersions

n/a

n/a

affected
n/a

References

43646
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2011:009
vendor-advisory
x_refsource_SUSE
71021
vdb-entry
x_refsource_OSVDB
ADV-2011-0752
vdb-entry
x_refsource_VUPEN
ADV-2011-0891
vdb-entry
x_refsource_VUPEN
GLSA-201206-33
vendor-advisory
x_refsource_GENTOO
FEDORA-2011-3355
vendor-advisory
x_refsource_FEDORA
43874
third-party-advisory
x_refsource_SECUNIA
FEDORA-2011-3394
vendor-advisory
x_refsource_FEDORA
APPLE-SA-2011-10-12-3
vendor-advisory
x_refsource_APPLE
ADV-2011-0611
vdb-entry
x_refsource_VUPEN
46767
vdb-entry
x_refsource_BID
RHSA-2011:0423
vendor-advisory
x_refsource_REDHAT
VU#555316
third-party-advisory
x_refsource_CERT-VN
1025179
vdb-entry
x_refsource_SECTRACK
RHSA-2011:0422
vendor-advisory
x_refsource_REDHAT
DSA-2233
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now