CVE-2011-0411
Publication date 16 March 2011
Last updated 24 July 2024
Ubuntu priority
The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.
Status
Package | Ubuntu Release | Status |
---|---|---|
postfix | ||
Notes
Patch details
References
Related Ubuntu Security Notices (USN)
- USN-1113-1
- Postfix vulnerabilities
- 18 April 2011