Plaintext Command Injection Vulnerability in Postfix Email Software
CVE-2011-0411

Currently unrated

Key Information:

Vendor

Postfix

Status
Vendor
CVE Published:
16 March 2011

What is CVE-2011-0411?

The STARTTLS implementation in Postfix prior to specific versions is vulnerable to plaintext command injection due to improper restriction of I/O buffering. This flaw allows a man-in-the-middle attacker to exploit encrypted SMTP sessions by injecting commands after the TLS handshake is completed, which can compromise the integrity of email communications.

References

EPSS Score

42% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.