First published: Wed Mar 16 2011(Updated: )
The STARTTLS implementation in the server in Ipswitch IMail 11.03 and earlier does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IPSWITCH IMail | =5.0 | |
IPSWITCH IMail | =6.0.4 | |
IPSWITCH IMail | =2006 | |
IPSWITCH IMail | =11.01 | |
IPSWITCH IMail | =8.1 | |
IPSWITCH IMail | =6.4 | |
IPSWITCH IMail | =6.0.5 | |
IPSWITCH IMail | =5.0.8 | |
IPSWITCH IMail | =11.02 | |
IPSWITCH IMail | =7.0.5 | |
IPSWITCH IMail | =5.0.7 | |
IPSWITCH IMail | ||
IPSWITCH IMail | =2006.2 | |
IPSWITCH IMail | =7.0.2 | |
IPSWITCH IMail | =11 | |
IPSWITCH IMail | =5.0.5 | |
IPSWITCH IMail | =7.0.1 | |
IPSWITCH IMail | =10.02 | |
IPSWITCH IMail | =7.1 | |
IPSWITCH IMail | =7.0.7 | |
IPSWITCH IMail | =7.0.6 | |
IPSWITCH IMail | =6.0.6 | |
IPSWITCH IMail | =2006.1 | |
IPSWITCH IMail | =6.1 | |
IPSWITCH IMail | =6.06 | |
IPSWITCH IMail | =6.0.1 | |
IPSWITCH IMail | =8.0.5 | |
IPSWITCH IMail | =6.00 | |
IPSWITCH IMail | =8.11 | |
IPSWITCH IMail | =6.0.3 | |
IPSWITCH IMail | =8.12 | |
IPSWITCH IMail | =6.3 | |
IPSWITCH IMail | <=11.03 | |
IPSWITCH IMail | =6.0 | |
IPSWITCH IMail | =6.0.2 | |
IPSWITCH IMail | =10 | |
IPSWITCH IMail | =8.13 | |
IPSWITCH IMail | =5.0.6 | |
IPSWITCH IMail | =8.01 | |
IPSWITCH IMail | =7.12 | |
IPSWITCH IMail | =7.0.4 | |
IPSWITCH IMail | =8.22 | |
IPSWITCH IMail | =6.2 | |
IPSWITCH IMail | =server_8.2_hotfix_2 | |
IPSWITCH IMail | =7.0.3 | |
IPSWITCH IMail | =10.01 | |
IPSWITCH IMail | =8.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.