Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-1926

Опубликовано: 23 мая 2011
Источник: ubuntu
Приоритет: high
CVSS2: 5.1

Описание

The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

hardy

ignored

end of life
lucid

released

2.2.13-19squeeze1build0.10.04.1
maverick

released

2.2.13-19squeeze1build0.10.10.1
natty

ignored

end of life
oneiric

ignored

end of life
precise

DNE

quantal

DNE

raring

DNE

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

DNE

lucid

DNE

maverick

DNE

natty

DNE

oneiric

not-affected

precise

not-affected

quantal

not-affected

raring

not-affected

Показывать по

Ссылки на источники

5.1 Medium

CVSS2

Связанные уязвимости

redhat
больше 14 лет назад

The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.

nvd
около 14 лет назад

The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.

debian
около 14 лет назад

The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not ...

github
около 3 лет назад

The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.

oracle-oval
около 14 лет назад

ELSA-2011-0859: cyrus-imapd security update (MODERATE)

5.1 Medium

CVSS2