Back to search
CVE-2011-0411
Published: Mar 16, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html
x_refsource_CONFIRM
multiple-starttls-command-execution(65932)
vdb-entry
x_refsource_XF
http://www.postfix.org/CVE-2011-0411.html
x_refsource_CONFIRM
43646
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2011:009
vendor-advisory
x_refsource_SUSE
71021
vdb-entry
x_refsource_OSVDB
ADV-2011-0752
vdb-entry
x_refsource_VUPEN
ADV-2011-0891
vdb-entry
x_refsource_VUPEN
GLSA-201206-33
vendor-advisory
x_refsource_GENTOO
FEDORA-2011-3355
vendor-advisory
x_refsource_FEDORA
43874
third-party-advisory
x_refsource_SECUNIA
FEDORA-2011-3394
vendor-advisory
x_refsource_FEDORA
http://www.kb.cert.org/vuls/id/MORO-8ELH6Z
x_refsource_CONFIRM
APPLE-SA-2011-10-12-3
vendor-advisory
x_refsource_APPLE
ADV-2011-0611
vdb-entry
x_refsource_VUPEN
46767
vdb-entry
x_refsource_BID
RHSA-2011:0423
vendor-advisory
x_refsource_REDHAT
VU#555316
third-party-advisory
x_refsource_CERT-VN
1025179
vdb-entry
x_refsource_SECTRACK
RHSA-2011:0422
vendor-advisory
x_refsource_REDHAT
http://support.apple.com/kb/HT5002
x_refsource_CONFIRM
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
x_refsource_CONFIRM
DSA-2233
vendor-advisory
x_refsource_DEBIAN
[oss-security] 20210810 STARTTLS vulnerabilities
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now