CVE Vulnerabilities

CVE-2011-1575

Published: May 23, 2011 | Modified: Feb 21, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted FTP sessions by sending a cleartext command that is processed after TLS is in place, related to a plaintext command injection attack, a similar issue to CVE-2011-0411.

Affected Software

Name Vendor Start Version End Version
Pure-ftpd Pureftpd * 1.0.29 (including)
Pure-ftpd Pureftpd 0.90 (including) 0.90 (including)
Pure-ftpd Pureftpd 0.91 (including) 0.91 (including)
Pure-ftpd Pureftpd 0.92 (including) 0.92 (including)
Pure-ftpd Pureftpd 0.93 (including) 0.93 (including)
Pure-ftpd Pureftpd 0.94 (including) 0.94 (including)
Pure-ftpd Pureftpd 0.95 (including) 0.95 (including)
Pure-ftpd Pureftpd 0.95-pre1 (including) 0.95-pre1 (including)
Pure-ftpd Pureftpd 0.95-pre2 (including) 0.95-pre2 (including)
Pure-ftpd Pureftpd 0.95-pre3 (including) 0.95-pre3 (including)
Pure-ftpd Pureftpd 0.95-pre4 (including) 0.95-pre4 (including)
Pure-ftpd Pureftpd 0.95.1 (including) 0.95.1 (including)
Pure-ftpd Pureftpd 0.95.2 (including) 0.95.2 (including)
Pure-ftpd Pureftpd 0.96 (including) 0.96 (including)
Pure-ftpd Pureftpd 0.96.1 (including) 0.96.1 (including)
Pure-ftpd Pureftpd 0.96pre1 (including) 0.96pre1 (including)
Pure-ftpd Pureftpd 0.97-final (including) 0.97-final (including)
Pure-ftpd Pureftpd 0.97.1 (including) 0.97.1 (including)
Pure-ftpd Pureftpd 0.97.2 (including) 0.97.2 (including)
Pure-ftpd Pureftpd 0.97.3 (including) 0.97.3 (including)
Pure-ftpd Pureftpd 0.97.4 (including) 0.97.4 (including)
Pure-ftpd Pureftpd 0.97.5 (including) 0.97.5 (including)
Pure-ftpd Pureftpd 0.97.6 (including) 0.97.6 (including)
Pure-ftpd Pureftpd 0.97.7 (including) 0.97.7 (including)
Pure-ftpd Pureftpd 0.97.7pre1 (including) 0.97.7pre1 (including)
Pure-ftpd Pureftpd 0.97.7pre2 (including) 0.97.7pre2 (including)
Pure-ftpd Pureftpd 0.97.7pre3 (including) 0.97.7pre3 (including)
Pure-ftpd Pureftpd 0.97pre1 (including) 0.97pre1 (including)
Pure-ftpd Pureftpd 0.97pre2 (including) 0.97pre2 (including)
Pure-ftpd Pureftpd 0.97pre3 (including) 0.97pre3 (including)
Pure-ftpd Pureftpd 0.97pre4 (including) 0.97pre4 (including)
Pure-ftpd Pureftpd 0.97pre5 (including) 0.97pre5 (including)
Pure-ftpd Pureftpd 0.98-final (including) 0.98-final (including)
Pure-ftpd Pureftpd 0.98.1 (including) 0.98.1 (including)
Pure-ftpd Pureftpd 0.98.2 (including) 0.98.2 (including)
Pure-ftpd Pureftpd 0.98.2a (including) 0.98.2a (including)
Pure-ftpd Pureftpd 0.98.3 (including) 0.98.3 (including)
Pure-ftpd Pureftpd 0.98.4 (including) 0.98.4 (including)
Pure-ftpd Pureftpd 0.98.5 (including) 0.98.5 (including)
Pure-ftpd Pureftpd 0.98.6 (including) 0.98.6 (including)
Pure-ftpd Pureftpd 0.98.7 (including) 0.98.7 (including)
Pure-ftpd Pureftpd 0.98pre1 (including) 0.98pre1 (including)
Pure-ftpd Pureftpd 0.98pre2 (including) 0.98pre2 (including)
Pure-ftpd Pureftpd 0.99 (including) 0.99 (including)
Pure-ftpd Pureftpd 0.99.1 (including) 0.99.1 (including)
Pure-ftpd Pureftpd 0.99.1a (including) 0.99.1a (including)
Pure-ftpd Pureftpd 0.99.1b (including) 0.99.1b (including)
Pure-ftpd Pureftpd 0.99.2 (including) 0.99.2 (including)
Pure-ftpd Pureftpd 0.99.2a (including) 0.99.2a (including)
Pure-ftpd Pureftpd 0.99.3 (including) 0.99.3 (including)
Pure-ftpd Pureftpd 0.99.4 (including) 0.99.4 (including)
Pure-ftpd Pureftpd 0.99.9 (including) 0.99.9 (including)
Pure-ftpd Pureftpd 0.99a (including) 0.99a (including)
Pure-ftpd Pureftpd 0.99b (including) 0.99b (including)
Pure-ftpd Pureftpd 0.99pre1 (including) 0.99pre1 (including)
Pure-ftpd Pureftpd 0.99pre2 (including) 0.99pre2 (including)
Pure-ftpd Pureftpd 1.0.0 (including) 1.0.0 (including)
Pure-ftpd Pureftpd 1.0.1 (including) 1.0.1 (including)
Pure-ftpd Pureftpd 1.0.2 (including) 1.0.2 (including)
Pure-ftpd Pureftpd 1.0.3 (including) 1.0.3 (including)
Pure-ftpd Pureftpd 1.0.4 (including) 1.0.4 (including)
Pure-ftpd Pureftpd 1.0.5 (including) 1.0.5 (including)
Pure-ftpd Pureftpd 1.0.6 (including) 1.0.6 (including)
Pure-ftpd Pureftpd 1.0.7 (including) 1.0.7 (including)
Pure-ftpd Pureftpd 1.0.8 (including) 1.0.8 (including)
Pure-ftpd Pureftpd 1.0.9 (including) 1.0.9 (including)
Pure-ftpd Pureftpd 1.0.10 (including) 1.0.10 (including)
Pure-ftpd Pureftpd 1.0.11 (including) 1.0.11 (including)
Pure-ftpd Pureftpd 1.0.12 (including) 1.0.12 (including)
Pure-ftpd Pureftpd 1.0.13a (including) 1.0.13a (including)
Pure-ftpd Pureftpd 1.0.14 (including) 1.0.14 (including)
Pure-ftpd Pureftpd 1.0.15 (including) 1.0.15 (including)
Pure-ftpd Pureftpd 1.0.16a (including) 1.0.16a (including)
Pure-ftpd Pureftpd 1.0.16b (including) 1.0.16b (including)
Pure-ftpd Pureftpd 1.0.16c (including) 1.0.16c (including)
Pure-ftpd Pureftpd 1.0.17 (including) 1.0.17 (including)
Pure-ftpd Pureftpd 1.0.17a (including) 1.0.17a (including)
Pure-ftpd Pureftpd 1.0.18 (including) 1.0.18 (including)
Pure-ftpd Pureftpd 1.0.19 (including) 1.0.19 (including)
Pure-ftpd Pureftpd 1.0.20 (including) 1.0.20 (including)
Pure-ftpd Pureftpd 1.0.21 (including) 1.0.21 (including)
Pure-ftpd Pureftpd 1.0.22 (including) 1.0.22 (including)
Pure-ftpd Pureftpd 1.0.24 (including) 1.0.24 (including)
Pure-ftpd Pureftpd 1.0.25 (including) 1.0.25 (including)
Pure-ftpd Pureftpd 1.0.26 (including) 1.0.26 (including)
Pure-ftpd Pureftpd 1.0.27 (including) 1.0.27 (including)
Pure-ftpd Pureftpd 1.0.28 (including) 1.0.28 (including)

References