|
|
| |
|
| |
inn: man-in-the-middle attack
| Package(s): | inn |
CVE #(s): | CVE-2012-3523
|
| Created: | October 2, 2012 |
Updated: | October 3, 2012 |
| Description: |
From the Mandriva advisory:
The STARTTLS implementation in INN's NNTP server for readers, nnrpd,
before 2.5.3 does not properly restrict I/O buffering, which allows
man-in-the-middle attackers to insert commands into encrypted sessions
by sending a cleartext command that is processed after TLS is in place,
related to a plaintext command injection attack, a similar issue to
CVE-2011-0411 (CVE-2012-3523). |
| Alerts: |
|
( Log in to post comments)
|
|
|