Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

postfix

postfixагент передачи почты (MTA — mail transfer agent).

Релизный цикл, информация об уязвимостях

Продукт: postfix
Вендор: postfix

График релизов

3.63.73.83.93.103.112021202220232024202520262027

Релизные элементы

KBВерсияБилдДата доступности
3.10.143.10.14
3.10.133.10.13
3.10.123.10.12
3.10.113.10.11
3.10.103.10.10
3.10.93.10.9
3.10.83.10.8
3.10.73.10.7
3.10.63.10.6
3.10.53.10.5

Показывать по

Недавние уязвимости postfix

Количество 91

oracle-oval логотип

ELSA-2011-0843

больше 15 лет назад

ELSA-2011-0843: postfix security update (MODERATE)

EPSS: Средний
debian логотип

CVE-2011-1720

больше 15 лет назад

The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x b ...

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2011-1720

больше 15 лет назад

The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.

CVSS2: 6.8
EPSS: Средний
ubuntu логотип

CVE-2011-1720

больше 15 лет назад

The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.

CVSS2: 6.8
EPSS: Средний
redhat логотип

CVE-2011-1720

больше 15 лет назад

The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.

CVSS2: 4.3
EPSS: Средний
oracle-oval логотип

ELSA-2011-0423

больше 15 лет назад

ELSA-2011-0423: postfix security update (MODERATE)

EPSS: Средний
debian логотип

CVE-2011-0411

больше 15 лет назад

The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x befo ...

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2011-0411

больше 15 лет назад

The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.

CVSS2: 6.8
EPSS: Средний
ubuntu логотип

CVE-2011-0411

больше 15 лет назад

The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.

CVSS2: 6.8
EPSS: Средний
redhat логотип

CVE-2011-0411

больше 15 лет назад

The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.

CVSS2: 4
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
oracle-oval логотип
ELSA-2011-0843

ELSA-2011-0843: postfix security update (MODERATE)

21%
Средний
больше 15 лет назад
debian логотип
CVE-2011-1720

The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x b ...

CVSS2: 6.8
21%
Средний
больше 15 лет назад
nvd логотип
CVE-2011-1720

The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.

CVSS2: 6.8
21%
Средний
больше 15 лет назад
ubuntu логотип
CVE-2011-1720

The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.

CVSS2: 6.8
21%
Средний
больше 15 лет назад
redhat логотип
CVE-2011-1720

The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.

CVSS2: 4.3
21%
Средний
больше 15 лет назад
oracle-oval логотип
ELSA-2011-0423

ELSA-2011-0423: postfix security update (MODERATE)

16%
Средний
больше 15 лет назад
debian логотип
CVE-2011-0411

The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x befo ...

CVSS2: 6.8
16%
Средний
больше 15 лет назад
nvd логотип
CVE-2011-0411

The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.

CVSS2: 6.8
16%
Средний
больше 15 лет назад
ubuntu логотип
CVE-2011-0411

The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.

CVSS2: 6.8
16%
Средний
больше 15 лет назад
redhat логотип
CVE-2011-0411

The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.

CVSS2: 4
16%
Средний
больше 15 лет назад

Уязвимостей на страницу


Поделиться