CVE Database
/

CVE-2012-3523

Back to search

CVE-2012-3523

Published: Nov 11, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

The STARTTLS implementation in nnrpd in INN before 2.5.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.

VendorProductVersions

n/a

n/a

affected
n/a

References

MDVSA-2012:156
vendor-advisory
x_refsource_MANDRIVA
50661
third-party-advisory
x_refsource_SECUNIA
openSUSE-SU-2012:1171
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now