PT-2011-3126 · Qmail · Netqmail
Wietse Venema
·
Publicado
2011-03-16
·
Atualizado
2017-08-17
·
CVE-2011-1431
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
netqmail versions 1.06
Description
The issue is related to the STARTTLS implementation in qmail-smtpd, which does not properly restrict I/O buffering. This allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place. The attack is referred to as a "plaintext command injection" attack.
Recommendations
For netqmail version 1.06, consider disabling the STARTTLS implementation until a patch is available to properly restrict I/O buffering and prevent plaintext command injection attacks. Restrict access to the SMTP service to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Netqmail