CVE Vulnerabilities

CVE-2011-1926

Published: May 23, 2011 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a plaintext command injection attack, a similar issue to CVE-2011-0411.

Affected Software

Name Vendor Start Version End Version
Cyrus_imap_server Cmu 2.2.12 2.2.12
Cyrus_imap_server Cmu 2.3.13 2.3.13
Cyrus_imap_server Cmu 2.2.13p1 2.2.13p1
Cyrus_imap_server Cmu 2.3.12 2.3.12
Cyrus_imap_server Cmu 2.4.1 2.4.1
Cyrus_imap_server Cmu 2.1.17 2.1.17
Cyrus_imap_server Cmu 2.4.5 2.4.5
Cyrus_imap_server Cmu 2.3.6 2.3.6
Cyrus_imap_server Cmu 2.3.0 2.3.0
Cyrus_imap_server Cmu 2.2.11 2.2.11
Cyrus_imap_server Cmu 2.3.14 2.3.14
Cyrus_imap_server Cmu 2.3.2 2.3.2
Cyrus_imap_server Cmu * 2.4.6
Cyrus_imap_server Cmu 2.4.0 2.4.0
Cyrus_imap_server Cmu 2.3.11 2.3.11
Cyrus_imap_server Cmu 2.3.8 2.3.8
Cyrus_imap_server Cmu 2.3.5 2.3.5
Cyrus_imap_server Cmu 2.2.9 2.2.9
Cyrus_imap_server Cmu 2.4.3 2.4.3
Cyrus_imap_server Cmu 2.4.4 2.4.4
Cyrus_imap_server Cmu 2.3.9 2.3.9
Cyrus_imap_server Cmu 2.3.10 2.3.10
Cyrus_imap_server Cmu 2.2.13 2.2.13
Cyrus_imap_server Cmu 2.1.16 2.1.16
Cyrus_imap_server Cmu 2.3.7 2.3.7
Cyrus_imap_server Cmu 2.2.8 2.2.8
Cyrus_imap_server Cmu 2.3.16 2.3.16
Cyrus_imap_server Cmu 2.0.17 2.0.17
Cyrus_imap_server Cmu 2.3.1 2.3.1
Cyrus_imap_server Cmu 2.4.2 2.4.2
Cyrus_imap_server Cmu 2.3.4 2.3.4
Cyrus_imap_server Cmu 2.2.10 2.2.10
Cyrus_imap_server Cmu 2.1.18 2.1.18
Cyrus_imap_server Cmu 2.3.3 2.3.3
Cyrus_imap_server Cmu 2.3.15 2.3.15

References