PT-2014-1690 · Nginx+1 · Nginx+1

Published

2014-08-05

·

Updated

2024-06-15

·

CVE-2014-3556

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions nginx versions 1.5.x through 1.6.0 nginx versions 1.7.x through 1.7.3
Description The issue allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack. This enables attackers to gain access to confidential information sent by the client.
Recommendations For nginx versions 1.5.x through 1.6.0, update to version 1.6.1 or later. For nginx versions 1.7.x through 1.7.3, update to version 1.7.4 or later.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1989
BDU:2015-00638
CVE-2014-3556
OPENSUSE-SU-2024:10044-1

Affected Products

Alt Linux
Nginx