← All CVEs

CVE-2011-0411

medium · 6.8

The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.

6.8
CVSS
16.3%
EPSS (exploit prob.)
97th
EPSS percentile
2011-03-16
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
postfixpostfix2.4
postfixpostfix2.4.0
postfixpostfix2.4.1
postfixpostfix2.4.2
postfixpostfix2.4.3
postfixpostfix2.4.4
postfixpostfix2.4.5
postfixpostfix2.4.6
postfixpostfix2.4.7
postfixpostfix2.4.8
postfixpostfix2.4.9
postfixpostfix2.4.10
postfixpostfix2.4.11
postfixpostfix2.4.12
postfixpostfix2.4.13
postfixpostfix2.4.14
postfixpostfix2.4.15
postfixpostfix2.5.0
postfixpostfix2.5.1
postfixpostfix2.5.2
postfixpostfix2.5.3
postfixpostfix2.5.4
postfixpostfix2.5.5
postfixpostfix2.5.6
postfixpostfix2.5.7
postfixpostfix2.5.8
postfixpostfix2.5.9
postfixpostfix2.5.10
postfixpostfix2.5.11
postfixpostfix2.6
postfixpostfix2.6.0
postfixpostfix2.6.1
postfixpostfix2.6.2
postfixpostfix2.6.3
postfixpostfix2.6.4
postfixpostfix2.6.5
postfixpostfix2.6.6
postfixpostfix2.6.7
postfixpostfix2.6.8
postfixpostfix2.7.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2011-0411