CVE-2011-0411
The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.3%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 16.33% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- postfix/postfix
- Source
- cret@cert.org
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056559.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056560.html
- http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html
- http://secunia.com/advisories/43646Vendor Advisory
- http://secunia.com/advisories/43874
- http://security.gentoo.org/glsa/glsa-201206-33.xml
- http://securitytracker.com/id?1025179
- http://support.apple.com/kb/HT5002
- http://www.debian.org/security/2011/dsa-2233
- http://www.kb.cert.org/vuls/id/555316US Government Resource
- http://www.kb.cert.org/vuls/id/MORO-8ELH6ZUS Government Resource
- http://www.openwall.com/lists/oss-security/2021/08/10/2
- http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html
- http://www.osvdb.org/71021
- http://www.postfix.org/CVE-2011-0411.htmlExploit, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0422.html
- http://www.redhat.com/support/errata/RHSA-2011-0423.html
- http://www.securityfocus.com/bid/46767
- http://www.vupen.com/english/advisories/2011/0611Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0752
- http://www.vupen.com/english/advisories/2011/0891
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65932
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056559.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056560.html
- http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html
- http://secunia.com/advisories/43646Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.