PT-2014-1690 · Nginx+1 · Nginx+1

Publicado

2014-08-05

·

Atualizado

2024-06-15

·

CVE-2014-3556

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions nginx versions 1.5.x through 1.6.0 nginx versions 1.7.x through 1.7.3
Description The issue allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack. This enables attackers to gain access to confidential information sent by the client.
Recommendations For nginx versions 1.5.x through 1.6.0, update to version 1.6.1 or later. For nginx versions 1.7.x through 1.7.3, update to version 1.7.4 or later.

Correção

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1989
BDU:2015-00638
CVE-2014-3556
OPENSUSE-SU-2024:10044-1

Produtos afetados

Alt Linux
Nginx