CVE Database
/

CVE-2011-1720

Back to search

CVE-2011-1720

Published: May 13, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.

VendorProductVersions

n/a

n/a

affected
n/a

References

44500
third-party-advisory
x_refsource_SECUNIA
47778
vdb-entry
x_refsource_BID
GLSA-201206-33
vendor-advisory
x_refsource_GENTOO
72259
vdb-entry
x_refsource_OSVDB
VU#727230
third-party-advisory
x_refsource_CERT-VN
1025521
vdb-entry
x_refsource_SECTRACK
8247
third-party-advisory
x_refsource_SREASON
SUSE-SA:2011:023
vendor-advisory
x_refsource_SUSE
MDVSA-2011:090
vendor-advisory
x_refsource_MANDRIVA
DSA-2233
vendor-advisory
x_refsource_DEBIAN
USN-1131-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now