LWN.net Logo

postfix: TLS plaintext injection

Package(s):postfix CVE #(s):CVE-2011-0411
Created:March 24, 2011 Updated:October 2, 2012
Description:

From the Postfix advisory:

The flaw allows an attacker to inject client commands into an SMTP session during the unprotected plaintext SMTP protocol phase (more on that below), such that the server will execute those commands during the SMTP-over-TLS protocol phase when all communication is supposed to be protected.

See this LWN article for more information.

Alerts:
SUSE SUSE-SR:2011:010 2011-05-31
Ubuntu USN-1113-1 2011-04-18
CentOS CESA-2011:0422 2011-04-14
CentOS CESA-2011:0422 2011-04-08
Red Hat RHSA-2011:0422-01 2011-04-06
Red Hat RHSA-2011:0423-01 2011-04-06
Fedora FEDORA-2011-3349 2011-03-15
SUSE SUSE-SR:2011:008 2011-05-03
Fedora FEDORA-2011-3394 2011-03-15
Fedora FEDORA-2011-3355 2011-03-15
SUSE SUSE-SR:2011:009 2011-05-17
Debian DSA-2233-1 2011-05-10
Pardus 2011-68 2011-04-07
openSUSE openSUSE-SU-2011:0389-1 2011-04-22
Gentoo 201206-33 2012-06-25

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds