CVE Vulnerabilities

CVE-2012-3523

Published: Nov 11, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
4 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The STARTTLS implementation in nnrpd in INN before 2.5.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a plaintext command injection attack, a similar issue to CVE-2011-0411.

Affected Software

NameVendorStart VersionEnd Version
InnIsc*2.5.2 (including)
InnIsc1.4 (including)1.4 (including)
InnIsc1.4sec (including)1.4sec (including)
InnIsc1.4sec2 (including)1.4sec2 (including)
InnIsc1.4unoff3 (including)1.4unoff3 (including)
InnIsc1.4unoff4 (including)1.4unoff4 (including)
InnIsc1.5 (including)1.5 (including)
InnIsc1.5.1 (including)1.5.1 (including)
InnIsc1.7 (including)1.7 (including)
InnIsc1.7.2 (including)1.7.2 (including)
InnIsc2.0 (including)2.0 (including)
InnIsc2.1 (including)2.1 (including)
InnIsc2.2 (including)2.2 (including)
InnIsc2.2.1 (including)2.2.1 (including)
InnIsc2.2.2 (including)2.2.2 (including)
InnIsc2.2.3 (including)2.2.3 (including)
InnIsc2.4.0 (including)2.4.0 (including)
InnUbuntuartful*
InnUbuntuhardy*
InnUbuntulucid*
InnUbuntunatty*
InnUbuntuoneiric*
InnUbuntuprecise*
InnUbuntuquantal*
InnUbunturaring*
InnUbuntusaucy*
InnUbuntuutopic*
InnUbuntuvivid*
InnUbuntuwily*
InnUbuntuyakkety*
InnUbuntuzesty*
Inn2Ubuntuhardy*
Inn2Ubuntulucid*
Inn2Ubuntunatty*
Inn2Ubuntuoneiric*
Inn2Ubuntuprecise*
Inn2Ubuntuupstream*

References