|
|
| |
|
| |
postfix: TLS plaintext injection
| Package(s): | postfix |
CVE #(s): | CVE-2011-0411
|
| Created: | March 24, 2011 |
Updated: | October 2, 2012 |
| Description: |
From the Postfix advisory:
The flaw allows an attacker to inject client commands into an SMTP session during the unprotected plaintext SMTP protocol phase (more on that below), such that the server will execute those commands during the SMTP-over-TLS protocol phase when all communication is supposed to be protected.
See this LWN article for more information. |
| Alerts: |
|
( Log in to post comments)
|
|
|