CVE-2011-0411
Last modified
CVE-2011-0411 is a vulnerability of currently unknown severity. The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.. EPSS estimates a 16.33% chance of exploitation in the next 30 days.
Description
The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Postfix | Postfix | 2.4 |
| Postfix | Postfix | 2.4.0 |
| Postfix | Postfix | 2.4.1 |
| Postfix | Postfix | 2.4.2 |
| Postfix | Postfix | 2.4.3 |
| Postfix | Postfix | 2.4.4 |
| Postfix | Postfix | 2.4.5 |
| Postfix | Postfix | 2.4.6 |
| Postfix | Postfix | 2.4.7 |
| Postfix | Postfix | 2.4.8 |
| Postfix | Postfix | 2.4.9 |
| Postfix | Postfix | 2.4.10 |
| Postfix | Postfix | 2.4.11 |
| Postfix | Postfix | 2.4.12 |
| Postfix | Postfix | 2.4.13 |
| Postfix | Postfix | 2.4.14 |
| Postfix | Postfix | 2.4.15 |
| Postfix | Postfix | 2.5.0 |
| Postfix | Postfix | 2.5.1 |
| Postfix | Postfix | 2.5.2 |
| Postfix | Postfix | 2.5.3 |
| Postfix | Postfix | 2.5.4 |
| Postfix | Postfix | 2.5.5 |
| Postfix | Postfix | 2.5.6 |
| Postfix | Postfix | 2.5.7 |
| Postfix | Postfix | 2.5.8 |
| Postfix | Postfix | 2.5.9 |
| Postfix | Postfix | 2.5.10 |
| Postfix | Postfix | 2.5.11 |
| Postfix | Postfix | 2.6 |
| Postfix | Postfix | 2.6.0 |
| Postfix | Postfix | 2.6.1 |
| Postfix | Postfix | 2.6.2 |
| Postfix | Postfix | 2.6.3 |
| Postfix | Postfix | 2.6.4 |
| Postfix | Postfix | 2.6.5 |
| Postfix | Postfix | 2.6.6 |
| Postfix | Postfix | 2.6.7 |
| Postfix | Postfix | 2.6.8 |
| Postfix | Postfix | 2.7.0 |
| Postfix | Postfix | 2.7.1 |
| Postfix | Postfix | 2.7.2 |
References
- http://secunia.com/advisories/43646Vendor Advisory
- http://www.kb.cert.org/vuls/id/555316US Government Resource
- http://www.kb.cert.org/vuls/id/MORO-8ELH6ZUS Government Resource
- http://www.postfix.org/CVE-2011-0411.htmlExploit, Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0611Vendor Advisory
- http://secunia.com/advisories/43646Vendor Advisory
- http://www.kb.cert.org/vuls/id/555316US Government Resource
- http://www.kb.cert.org/vuls/id/MORO-8ELH6ZUS Government Resource
- http://www.postfix.org/CVE-2011-0411.htmlExploit, Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0611Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-0411?
How severe is CVE-2011-0411?
How do I fix CVE-2011-0411?
Are you affected by CVE-2011-0411?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
