Search

Find a vulnerability

Search criteria

    39 vulnerabilities by postfix

    CERTFR-2026-AVI-1141

    Vulnerability from certfr_avis - Published: 2026-09-09 - Updated: 2026-09-09

    De multiples vulnérabilités ont été découvertes dans Postfix. Elles permettent à un attaquant de provoquer un déni de service à distance et un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Postfix Postfix Postfix versions 3.7.x antérieures à 3.7.23
    Postfix Postfix Postfix versions 3.11.x antérieures à 3.11.7
    Postfix Postfix Postfix versions 3.8.x antérieures à 3.8.21
    Postfix Postfix Postfix versions 3.9.x antérieures à 3.9.15
    Postfix Postfix Postfix versions antérieures à 3.5.28
    Postfix Postfix Postfix versions 3.6.x antérieures à 3.6.21
    Postfix Postfix Postfix versions 3.10.x antérieures à 3.10.14
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Postfix versions 3.7.x ant\u00e9rieures \u00e0 3.7.23",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.11.x ant\u00e9rieures \u00e0 3.11.7",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.8.x ant\u00e9rieures \u00e0 3.8.21",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.9.x ant\u00e9rieures \u00e0 3.9.15",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions ant\u00e9rieures \u00e0 3.5.28",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.6.x ant\u00e9rieures \u00e0 3.6.21",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.10.x ant\u00e9rieures \u00e0 3.10.14",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [],
      "initial_release_date": "2026-09-09T00:00:00",
      "last_revision_date": "2026-09-09T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1141",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-09T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Postfix. Elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance et un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans Postfix",
      "vendor_advisories": [
        {
          "published_at": "2026-09-07",
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix postfix-3.11.7",
          "url": "http://www.postfix.org/announcements/postfix-3.11.7.html"
        }
      ]
    }

    CERTFR-2026-AVI-0993

    Vulnerability from certfr_avis - Published: 2026-08-11 - Updated: 2026-08-11

    De multiples vulnérabilités ont été découvertes dans Postfix. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Postfix Postfix Postfix versions 3.7.x antérieures à 3.7.22
    Postfix Postfix Postfix versions 3.6.x antérieures à 3.6.20
    Postfix Postfix Postfix versions 3.9.x antérieures à 3.9.14
    Postfix Postfix Postfix versions 3.10.x antérieures à 3.10.13
    Postfix Postfix Postfix versions antérieures à 3.5.27
    Postfix Postfix Postfix versions 3.8.x antérieures à 3.8.20
    Postfix Postfix Postfix versions 3.11.x antérieures à 3.11.6
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Postfix versions 3.7.x ant\u00e9rieures \u00e0 3.7.22",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.6.x ant\u00e9rieures \u00e0 3.6.20",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.9.x ant\u00e9rieures \u00e0 3.9.14",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.10.x ant\u00e9rieures \u00e0 3.10.13",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions ant\u00e9rieures \u00e0 3.5.27",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.8.x ant\u00e9rieures \u00e0 3.8.20",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.11.x ant\u00e9rieures \u00e0 3.11.6",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [],
      "initial_release_date": "2026-08-11T00:00:00",
      "last_revision_date": "2026-08-11T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0993",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-08-11T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Postfix. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance, un contournement de la politique de s\u00e9curit\u00e9 et un probl\u00e8me de s\u00e9curit\u00e9 non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans Postfix",
      "vendor_advisories": [
        {
          "published_at": "2026-08-10",
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix postfix-3.11.6",
          "url": "http://www.postfix.org/announcements/postfix-3.11.6.html"
        }
      ]
    }

    CERTFR-2026-AVI-0842

    Vulnerability from certfr_avis - Published: 2026-07-07 - Updated: 2026-07-07

    De multiples vulnérabilités ont été découvertes dans Postfix. Elles permettent à un attaquant de provoquer un déni de service et un problème de sécurité non spécifié par l'éditeur.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Postfix Postfix Postfix versions 3.11.x antérieures à 3.11.5
    Postfix Postfix Postfix versions 3.6.x antérieures à 3.6.19
    Postfix Postfix Postfix versions 3.10.x antérieures à 3.10.12
    Postfix Postfix Postfix versions 3.8.x antérieures à 3.8.19
    Postfix Postfix Postfix versions antérieures à 3.5.26
    Postfix Postfix Postfix versions 3.7.x antérieures à 3.7.21
    Postfix Postfix Postfix versions 3.9.x antérieures à 3.9.13
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Postfix versions 3.11.x ant\u00e9rieures \u00e0 3.11.5",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.6.x ant\u00e9rieures \u00e0 3.6.19",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.10.x ant\u00e9rieures \u00e0 3.10.12",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.8.x ant\u00e9rieures \u00e0 3.8.19",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions ant\u00e9rieures \u00e0 3.5.26",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.7.x ant\u00e9rieures \u00e0 3.7.21",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.9.x ant\u00e9rieures \u00e0 3.9.13",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [],
      "initial_release_date": "2026-07-07T00:00:00",
      "last_revision_date": "2026-07-07T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0842",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-07-07T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "D\u00e9ni de service"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Postfix. Elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service et un probl\u00e8me de s\u00e9curit\u00e9 non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans Postfix",
      "vendor_advisories": [
        {
          "published_at": "2026-07-06",
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix postfix-3.11.5",
          "url": "http://www.postfix.org/announcements/postfix-3.11.5.html"
        }
      ]
    }

    CERTFR-2026-AVI-0793

    Vulnerability from certfr_avis - Published: 2026-06-22 - Updated: 2026-06-22

    De multiples vulnérabilités ont été découvertes dans Postfix. Elles permettent à un attaquant de provoquer un déni de service à distance et un problème de sécurité non spécifié par l'éditeur.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Postfix Postfix Postfix versions 3.11.x antérieures à 3.11.4
    Postfix Postfix Postfix versions 3.10.x antérieures à 3.10.11
    Postfix Postfix Postfix versions 3.9.x antérieures à 3.9.12
    Postfix Postfix Postfix versions antérieures à 3.8.18
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Postfix versions 3.11.x ant\u00e9rieures \u00e0 3.11.4",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.10.x ant\u00e9rieures \u00e0 3.10.11",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.9.x ant\u00e9rieures \u00e0 3.9.12",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions ant\u00e9rieures \u00e0 3.8.18",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [],
      "initial_release_date": "2026-06-22T00:00:00",
      "last_revision_date": "2026-06-22T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0793",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-06-22T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Postfix. Elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance et un probl\u00e8me de s\u00e9curit\u00e9 non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans Postfix",
      "vendor_advisories": [
        {
          "published_at": "2026-06-17",
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix postfix-3.11.4",
          "url": "http://www.postfix.org/announcements/postfix-3.11.4.html"
        }
      ]
    }

    CERTFR-2025-AVI-1040

    Vulnerability from certfr_avis - Published: 2025-11-26 - Updated: 2025-11-26

    Une vulnérabilité a été découverte dans Postfix. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité et un déni de service.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Postfix Postfix Postfix versions 3.10.x antérieures à 3.10.6
    Postfix Postfix Postfix versions antérieures à 3.7.18
    Postfix Postfix Postfix versions 3.8.x antérieures à 3.8.13
    Postfix Postfix Postfix versions 3.9.x antérieures à 3.9.7
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Postfix versions 3.10.x ant\u00e9rieures \u00e0 3.10.6",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions ant\u00e9rieures \u00e0 3.7.18",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.8.x ant\u00e9rieures \u00e0 3.8.13",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.9.x ant\u00e9rieures \u00e0 3.9.7",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [],
      "initial_release_date": "2025-11-26T00:00:00",
      "last_revision_date": "2025-11-26T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-1040",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-11-26T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans Postfix. Elle permet \u00e0 un attaquant de provoquer un contournement de la politique de s\u00e9curit\u00e9 et un d\u00e9ni de service.",
      "title": "Vuln\u00e9rabilit\u00e9 dans Postfix",
      "vendor_advisories": [
        {
          "published_at": "2025-11-25",
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix postfix-3.10.6",
          "url": "http://www.postfix.org/announcements/postfix-3.10.6.html"
        }
      ]
    }

    CERTFR-2024-AVI-0058

    Vulnerability from certfr_avis - Published: 2024-01-22 - Updated: 2024-01-22

    Une vulnérabilité a été découverte dans Postfix. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    D'après l'éditeur, les versions 3.8.5, 3.7.10, 3.6.14 et 3.5.24 apportent un correctif à long terme contrairement aux versions 3.8.4, 3.7.9, 3.6.13 et 3.5.23 qui constituaient une mesure de contournement.

    Impacted products
    Vendor Product Description
    Postfix Postfix Postfix versions antérieures à 3.8.5, 3.7.10, 3.6.14 et 3.5.24
    References
    Bulletin de sécurité Postfix 2023-12-18 vendor-advisory
    Bulletin de sécurité Postfix 3.8.5 2024-01-22 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Postfix versions ant\u00e9rieures \u00e0 3.8.5, 3.7.10, 3.6.14 et 3.5.24",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "D\u0027apr\u00e8s l\u0027\u00e9diteur, les versions 3.8.5, 3.7.10, 3.6.14 et 3.5.24 apportent un correctif \u00e0 long terme contrairement aux versions 3.8.4, 3.7.9, 3.6.13 et 3.5.23 qui constituaient une mesure de contournement.",
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2023-51764",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-51764"
        }
      ],
      "initial_release_date": "2024-01-22T00:00:00",
      "last_revision_date": "2024-01-22T00:00:00",
      "links": [],
      "reference": "CERTFR-2024-AVI-0058",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2024-01-22T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans Postfix. Elle permet \u00e0 un\nattaquant de provoquer un contournement de la politique de s\u00e9curit\u00e9.\n",
      "title": "Vuln\u00e9rabilit\u00e9 dans Postfix",
      "vendor_advisories": [
        {
          "published_at": "2023-12-18",
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix",
          "url": "https://www.postfix.org/smtp-smuggling.html"
        },
        {
          "published_at": "2024-01-22",
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix 3.8.5",
          "url": "https://www.postfix.org/announcements/postfix-3.8.5.html"
        }
      ]
    }

    CERTFR-2023-AVI-1057

    Vulnerability from certfr_avis - Published: 2023-12-22 - Updated: 2023-12-26

    De multiples vulnérabilités ont été corrigées dans Postfix. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    Postfix Postfix Postfix versions antérieures à 3.8.4, 3.7.9, 3.6.13 et 3.5.23

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Postfix versions ant\u00e9rieures \u00e0 3.8.4, 3.7.9, 3.6.13 et 3.5.23",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [],
      "initial_release_date": "2023-12-22T00:00:00",
      "last_revision_date": "2023-12-26T00:00:00",
      "links": [
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix 3.8.4 du 22 d\u00e9cembre 2022",
          "url": "https://www.postfix.org/announcements/postfix-3.8.4.html"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix 3.6.13 du 22 d\u00e9cembre 2022",
          "url": "https://www.postfix.org/announcements/postfix-3.6.13.html"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix 3.7.9 du 22 d\u00e9cembre 2022",
          "url": "https://www.postfix.org/announcements/postfix-3.7.9.html"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix 3.5.23 du 22 d\u00e9cembre 2022",
          "url": "https://www.postfix.org/announcements/postfix-3.5.23.html"
        }
      ],
      "reference": "CERTFR-2023-AVI-1057",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2023-12-22T00:00:00.000000"
        },
        {
          "description": "Ajout des bulletins de s\u00e9curit\u00e9 Postfix du 22 d\u00e9cembre 2023.",
          "revision_date": "2023-12-26T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 corrig\u00e9es dans Postfix. Elles\npermettent \u00e0 un attaquant de provoquer un contournement de la politique\nde s\u00e9curit\u00e9.\n",
      "title": "Vuln\u00e9rabilit\u00e9 dans Postfix",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix 3.6.13 du 22 d\u00e9cembre 2023",
          "url": null
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix 3.7.9 du 22 d\u00e9cembre 2023",
          "url": null
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix du 20 d\u00e9cembre 2023",
          "url": "https://www.postfix.org/smtp-smuggling.html"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix 3.8.4 du 22 d\u00e9cembre 2023",
          "url": null
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix 3.5.23 du 22 d\u00e9cembre 2023",
          "url": null
        }
      ]
    }

    CERTFR-2023-AVI-0437

    Vulnerability from certfr_avis - Published: 2023-06-07 - Updated: 2023-06-07

    De multiples vulnérabilités ont été découvertes dans Postfix. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    Postfix Postfix Postfix versions 3.5.x antérieures à 3.5.20
    Postfix Postfix Postfix versions 3.8.x antérieures à 3.8.1
    Postfix Postfix Postfix versions 3.6.x antérieures à 3.6.10
    Postfix Postfix Postfix versions 3.7.x antérieures à 3.7.6
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Postfix versions 3.5.x ant\u00e9rieures \u00e0 3.5.20",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.8.x ant\u00e9rieures \u00e0 3.8.1",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.6.x ant\u00e9rieures \u00e0 3.6.10",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.7.x ant\u00e9rieures \u00e0 3.7.6",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [],
      "initial_release_date": "2023-06-07T00:00:00",
      "last_revision_date": "2023-06-07T00:00:00",
      "links": [
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix du 05 juin 2023",
          "url": "http://www.postfix.org/announcements/postfix-3.8.1.html"
        }
      ],
      "reference": "CERTFR-2023-AVI-0437",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2023-06-07T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Postfix. Elles\npermettent \u00e0 un attaquant de provoquer un probl\u00e8me de s\u00e9curit\u00e9 non\nsp\u00e9cifi\u00e9 par l\u0027\u00e9diteur.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans Postfix",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix 3.8.1 du 05 juin 2023",
          "url": null
        }
      ]
    }

    CERTFR-2023-AVI-0328

    Vulnerability from certfr_avis - Published: 2023-04-20 - Updated: 2023-04-20

    De multiples vulnérabilités ont été découvertes dans Postfix. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité et un déni de service.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    Postfix Postfix Postfix versions 3.4.x antérieures à 3.4.29
    Postfix Postfix Postfix versions 3.5.x antérieures à 3.5.19
    Postfix Postfix Postfix versions 3.7.x antérieures à 3.7.5
    Postfix Postfix Postfix versions antérieures à 3.8.0
    Postfix Postfix Postfix versions 3.6.x antérieures à 3.6.9

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Postfix versions 3.4.x ant\u00e9rieures \u00e0 3.4.29",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.5.x ant\u00e9rieures \u00e0 3.5.19",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.7.x ant\u00e9rieures \u00e0 3.7.5",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions ant\u00e9rieures \u00e0 3.8.0",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.6.x ant\u00e9rieures \u00e0 3.6.9",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [],
      "initial_release_date": "2023-04-20T00:00:00",
      "last_revision_date": "2023-04-20T00:00:00",
      "links": [
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix du 18 avril 2023",
          "url": "http://www.postfix.org/announcements/postfix-3.7.5.html"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix du 18 avril 2023",
          "url": "http://www.postfix.org/announcements/postfix-3.8.0.html"
        }
      ],
      "reference": "CERTFR-2023-AVI-0328",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2023-04-20T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Postfix. Elles\npermettent \u00e0 un attaquant de provoquer un contournement de la politique\nde s\u00e9curit\u00e9 et un d\u00e9ni de service.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans Postfix",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix 3.7.5 du 18 avril 2023",
          "url": null
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix 3.8.0 du 18 avril 2023",
          "url": null
        }
      ]
    }

    CERTFR-2022-AVI-358

    Vulnerability from certfr_avis - Published: 2022-04-19 - Updated: 2022-04-19

    De multiples vulnérabilités ont été découvertes dans Postfix. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité et une élévation de privilèges.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    Postfix Postfix Postfix versions 3.5.x antérieures à 3.5.16
    Postfix Postfix Postfix versions 3.6.x antérieures à 3.6.6
    Postfix Postfix Postfix versions 3.7.x antérieures à 3.7.1
    Postfix Postfix Postfix versions 3.4.x antérieures à 3.4.26
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Postfix versions 3.5.x ant\u00e9rieures \u00e0 3.5.16",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.6.x ant\u00e9rieures \u00e0 3.6.6",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.7.x ant\u00e9rieures \u00e0 3.7.1",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.4.x ant\u00e9rieures \u00e0 3.4.26",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [],
      "initial_release_date": "2022-04-19T00:00:00",
      "last_revision_date": "2022-04-19T00:00:00",
      "links": [],
      "reference": "CERTFR-2022-AVI-358",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2022-04-19T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Postfix. Elles\npermettent \u00e0 un attaquant de provoquer un contournement de la politique\nde s\u00e9curit\u00e9 et une \u00e9l\u00e9vation de privil\u00e8ges.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans Postfix",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix 3.7.1 du 18 avril 2022",
          "url": "https://www.postfix.org/announcements/postfix-3.7.1.html"
        }
      ]
    }

    CERTFR-2022-AVI-117

    Vulnerability from certfr_avis - Published: 2022-02-07 - Updated: 2022-02-07

    De multiples vulnérabilités ont été découvertes dans Postfix. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité, une atteinte à l'intégrité des données et une élévation de privilèges.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Postfix Postfix Postfix versions 3.4.x antérieures à 3.4.25
    Postfix Postfix Postfix versions 3.6.x antérieures à 3.6.5 ou 3.7.0
    Postfix Postfix Postfix versions 3.3.x antérieures à 3.3.22
    Postfix Postfix Postfix versions 3.5.x antérieures à 3.5.15
    References
    Bulletin de sécurité Postfix 3.7.0 2022-02-05 vendor-advisory
    Bulletin de sécurité Postfix 3.6.5 2022-02-05 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Postfix versions 3.4.x ant\u00e9rieures \u00e0 3.4.25",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.6.x ant\u00e9rieures \u00e0 3.6.5 ou 3.7.0",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.3.x ant\u00e9rieures \u00e0 3.3.22",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.5.x ant\u00e9rieures \u00e0 3.5.15",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [],
      "initial_release_date": "2022-02-07T00:00:00",
      "last_revision_date": "2022-02-07T00:00:00",
      "links": [],
      "reference": "CERTFR-2022-AVI-117",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2022-02-07T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Postfix. Elles\npermettent \u00e0 un attaquant de provoquer un contournement de la politique\nde s\u00e9curit\u00e9, une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es et une \u00e9l\u00e9vation de\nprivil\u00e8ges.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans Postfix",
      "vendor_advisories": [
        {
          "published_at": "2022-02-05",
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix 3.7.0",
          "url": "https://www.postfix.org/announcements/postfix-3.7.0.html"
        },
        {
          "published_at": "2022-02-05",
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix 3.6.5",
          "url": "https://www.postfix.org/announcements/postfix-3.6.5.html"
        }
      ]
    }

    CERTFR-2022-AVI-045

    Vulnerability from certfr_avis - Published: 2022-01-17 - Updated: 2022-01-17

    De multiples vulnérabilités ont été découvertes dans Postfix. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, un contournement de la politique de sécurité et une atteinte à l'intégrité des données.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    Postfix Postfix Postfix versions 3.3.x antérieures à 3.3.21
    Postfix Postfix Postfix versions 3.4.x antérieures à 3.4.24
    Postfix Postfix Postfix versions 3.6.x antérieures à 3.6.4
    Postfix Postfix Postfix versions 3.5.x antérieures à 3.5.14
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Postfix versions 3.3.x ant\u00e9rieures \u00e0 3.3.21",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.4.x ant\u00e9rieures \u00e0 3.4.24",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.6.x ant\u00e9rieures \u00e0 3.6.4",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.5.x ant\u00e9rieures \u00e0 3.5.14",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [],
      "initial_release_date": "2022-01-17T00:00:00",
      "last_revision_date": "2022-01-17T00:00:00",
      "links": [],
      "reference": "CERTFR-2022-AVI-045",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2022-01-17T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Postfix. Elles\npermettent \u00e0 un attaquant de provoquer un probl\u00e8me de s\u00e9curit\u00e9 non\nsp\u00e9cifi\u00e9 par l\u0027\u00e9diteur, un contournement de la politique de s\u00e9curit\u00e9 et\nune atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans Postfix",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix du 16 janvier 2022",
          "url": "http://www.postfix.org/announcements/postfix-3.6.4.html"
        }
      ]
    }

    CERTFR-2021-AVI-851

    Vulnerability from certfr_avis - Published: 2021-11-09 - Updated: 2021-11-09

    Une vulnérabilité a été découverte dans Postfix. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    Postfix Postfix Postfix versions antérieures à 3.6.3, 3.5.13, 3.4.23, 3.3.20
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Postfix versions ant\u00e9rieures \u00e0 3.6.3, 3.5.13, 3.4.23, 3.3.20",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [],
      "initial_release_date": "2021-11-09T00:00:00",
      "last_revision_date": "2021-11-09T00:00:00",
      "links": [],
      "reference": "CERTFR-2021-AVI-851",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2021-11-09T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans Postfix. Elle permet \u00e0 un\nattaquant de provoquer un contournement de la politique de s\u00e9curit\u00e9.\n",
      "title": "Vuln\u00e9rabilit\u00e9 dans Postfix",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix 3.6.3 du 9 novembre 2021",
          "url": "http://www.postfix.org/announcements/postfix-3.6.3.html"
        }
      ]
    }

    CERTFR-2019-AVI-456

    Vulnerability from certfr_avis - Published: 2019-09-23 - Updated: 2019-09-23

    De multiples vulnérabilités ont été découvertes dans Postfix. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur et un déni de service à distance.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    Postfix Postfix Postfix versions 3.1.x antérieures à 3.1.14
    Postfix Postfix Postfix versions 3.2.x antérieures à 3.2.11
    Postfix Postfix Postfix versions 3.4.x antérieures à 3.4.7
    Postfix Postfix Postfix versions 3.3.x antérieures à 3.3.6
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Postfix versions 3.1.x ant\u00e9rieures \u00e0 3.1.14",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.2.x ant\u00e9rieures \u00e0 3.2.11",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.4.x ant\u00e9rieures \u00e0 3.4.7",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 3.3.x ant\u00e9rieures \u00e0 3.3.6",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [],
      "initial_release_date": "2019-09-23T00:00:00",
      "last_revision_date": "2019-09-23T00:00:00",
      "links": [],
      "reference": "CERTFR-2019-AVI-456",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2019-09-23T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Postfix. Elles\npermettent \u00e0 un attaquant de provoquer un probl\u00e8me de s\u00e9curit\u00e9 non\nsp\u00e9cifi\u00e9 par l\u0027\u00e9diteur et un d\u00e9ni de service \u00e0 distance.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans Postfix",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Postfix du 22 septembre 2019",
          "url": "http://www.postfix.org/announcements/postfix-3.4.7.html"
        }
      ]
    }

    CERTA-2011-AVI-146

    Vulnerability from certfr_avis - Published: 2011-03-10 - Updated: 2011-03-10

    Une vulnérabilité dans la gestion du protocole TLS permet à un attaquant d'insérer des commandes dans les communications SMTP d'une victime.

    Description

    Il est possible à un attaquant en position d'interception (man in the middle) d'insérer des commandes SMTP lorsqu'un client souhaite utiliser une connexion sécurisée au moyen de la commande STARTTLS, qui est un message transmis en clair. Ces commandes sont alors interprétées par le serveur dans le contexte d'une connexion sécurisée.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    Postfix Postfix Postfix versions 2.5.x strictement inférieures à 2.5.12 ;
    Postfix Postfix Postfix versions 2.6.x strictement inférieures à 2.6.9 ;
    Postfix Postfix Postfix versions 2.7.x strictement inférieures à 2.7.3 ;
    Postfix Postfix Postfix versions 2.4.x strictement inférieures à 2.4.16.

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Postfix versions 2.5.x strictement inf\u00e9rieures \u00e0 2.5.12 ;",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 2.6.x strictement inf\u00e9rieures \u00e0 2.6.9 ;",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 2.7.x strictement inf\u00e9rieures \u00e0 2.7.3 ;",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        },
        {
          "description": "Postfix versions 2.4.x strictement inf\u00e9rieures \u00e0 2.4.16.",
          "product": {
            "name": "Postfix",
            "vendor": {
              "name": "Postfix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Description\n\nIl est possible \u00e0 un attaquant en position d\u0027interception (man in the\nmiddle) d\u0027ins\u00e9rer des commandes SMTP lorsqu\u0027un client souhaite utiliser\nune connexion s\u00e9curis\u00e9e au moyen de la commande STARTTLS, qui est un\nmessage transmis en clair. Ces commandes sont alors interpr\u00e9t\u00e9es par le\nserveur dans le contexte d\u0027une connexion s\u00e9curis\u00e9e.\n\n## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2011-0411",
          "url": "https://www.cve.org/CVERecord?id=CVE-2011-0411"
        }
      ],
      "initial_release_date": "2011-03-10T00:00:00",
      "last_revision_date": "2011-03-10T00:00:00",
      "links": [
        {
          "title": "Description d\u00e9taill\u00e9e de la vuln\u00e9rabilit\u00e9 CVE-2011-0411 :",
          "url": "http://www.postfix.org/CVE-2011-0411.html"
        }
      ],
      "reference": "CERTA-2011-AVI-146",
      "revisions": [
        {
          "description": "version initiale.",
          "revision_date": "2011-03-10T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 dans la gestion du protocole TLS permet \u00e0 un attaquant\nd\u0027ins\u00e9rer des commandes dans les communications SMTP d\u0027une victime.\n",
      "title": "Vuln\u00e9rabilit\u00e9 dans Postfix",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de mise \u00e0 jour Postfix du 7 mars 2011",
          "url": "http://www.postfix.org/announcements/postfix-2.7.3.html"
        }
      ]
    }

    CVE-2026-43964 (GCVE-0-2026-43964)

    Vulnerability from nvd – Published: 2026-05-04 18:10 – Updated: 2026-08-20 12:31
    VLAI
    Summary
    Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-04 19:49 UTC
    CWE
    Impacted products
    Vendor Product Version
    Postfix Postfix Affected: 2.3 , < 3.8.16 (custom)
    Affected: 3.9 , < 3.9.10 (custom)
    Affected: 3.10 , < 3.10.9 (custom)
        cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*
        cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*
        cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 10 Unaffected: 2:3.8.5-10.el10_2 , < * (rpm)
        cpe:/o:redhat:enterprise_linux:10.2
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support Unaffected: 2:3.8.5-8.el10_0.1 , < * (rpm)
        cpe:/o:redhat:enterprise_linux_eus:10.0
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support Unaffected: 2:2.10.1-9.el7_9.1 , < * (rpm)
        cpe:/o:redhat:rhel_els:7
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 8 Unaffected: 2:3.5.8-8.el8_10 , < * (rpm)
        cpe:/a:redhat:enterprise_linux:8
        cpe:/o:redhat:enterprise_linux:8
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Unaffected: 2:3.5.8-1.el8_4.1 , < * (rpm)
        cpe:/a:redhat:rhel_aus:8.4
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Unaffected: 2:3.5.8-1.el8_4.1 , < * (rpm)
        cpe:/a:redhat:rhel_eus_long_life:8.4
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Unaffected: 2:3.5.8-4.el8_6.1 , < * (rpm)
        cpe:/a:redhat:rhel_aus:8.6
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Unaffected: 2:3.5.8-4.el8_6.1 , < * (rpm)
        cpe:/a:redhat:rhel_eus_long_life:8.6
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service Unaffected: 2:3.5.8-4.el8_8.1 , < * (rpm)
        cpe:/a:redhat:rhel_tus:8.8
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Unaffected: 2:3.5.8-4.el8_8.1 , < * (rpm)
        cpe:/a:redhat:rhel_e4s:8.8
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 9 Unaffected: 2:3.5.25-3.el9_8 , < * (rpm)
        cpe:/a:redhat:enterprise_linux:9
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 6     cpe:/o:redhat:enterprise_linux:6
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-43964",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-04T19:49:30.949584Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-04T19:49:41.165Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2026-05-04T22:21:13.917Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2026/05/04/30"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/o:redhat:enterprise_linux:10.2"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 10",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.8.5-10.el10_2",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/o:redhat:enterprise_linux_eus:10.0"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 10.0 Extended Update Support",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.8.5-8.el10_0.1",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/o:redhat:rhel_els:7"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:2.10.1-9.el7_9.1",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:enterprise_linux:8",
                  "cpe:/o:redhat:enterprise_linux:8"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 8",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.5.8-8.el8_10",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:rhel_aus:8.4"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.5.8-1.el8_4.1",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:rhel_eus_long_life:8.4"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.5.8-1.el8_4.1",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:rhel_aus:8.6"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.5.8-4.el8_6.1",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:rhel_eus_long_life:8.6"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.5.8-4.el8_6.1",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:rhel_tus:8.8"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.5.8-4.el8_8.1",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:rhel_e4s:8.8"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.5.8-4.el8_8.1",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:enterprise_linux:9"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 9",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.5.25-3.el9_8",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/o:redhat:enterprise_linux:6"
                ],
                "defaultStatus": "unknown",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 6",
                "vendor": "Red Hat"
              }
            ],
            "datePublic": "2026-05-04T18:10:10.509Z",
            "descriptions": [
              {
                "lang": "en",
                "value": "A flaw was found in Postfix. This issue occurs when processing enhanced status codes, specifically an enhanced status code that lacks text following the third number. Depending on the configuration of the server, this allows a remote attacker to cause a buffer over-read of only 1 byte, leading to an application crash and resulting in a denial of service."
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "namespace": "https://access.redhat.com/security/updates/classification/",
                    "value": "Important"
                  },
                  "type": "Red Hat severity rating"
                }
              },
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                },
                "format": "CVSS"
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-193",
                    "description": "Off-by-one Error",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-20T12:31:52.721Z",
              "orgId": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "shortName": "redhat-SADP"
            },
            "references": [
              {
                "tags": [
                  "vdb-entry",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/security/cve/CVE-2026-43964"
              },
              {
                "name": "RHBZ#2466488",
                "tags": [
                  "issue-tracking",
                  "x_refsource_REDHAT"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466488"
              },
              {
                "tags": [
                  "x_sadp-csaf-vex"
                ],
                "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43964.json"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:57174"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:51436"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:25930"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:25932"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:26205"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:51034"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:50963"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:50964"
              }
            ],
            "solutions": [
              {
                "lang": "en",
                "value": "RHSA-2026:57174: Red Hat Enterprise Linux Server (v. 7 ELS)"
              },
              {
                "lang": "en",
                "value": "RHSA-2026:51436: Red Hat Enterprise Linux AppStream EUS (v. 10.0)"
              },
              {
                "lang": "en",
                "value": "RHSA-2026:25930: Red Hat Enterprise Linux AppStream (v. 10)"
              },
              {
                "lang": "en",
                "value": "RHSA-2026:25932: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux BaseOS (v. 8)"
              },
              {
                "lang": "en",
                "value": "RHSA-2026:26205: Red Hat Enterprise Linux AppStream (v. 9)"
              },
              {
                "lang": "en",
                "value": "RHSA-2026:51034: Red Hat Enterprise Linux BaseOS AUS (v.8.4), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)"
              },
              {
                "lang": "en",
                "value": "RHSA-2026:50963: Red Hat Enterprise Linux BaseOS AUS (v.8.6), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)"
              },
              {
                "lang": "en",
                "value": "RHSA-2026:50964: Red Hat Enterprise Linux BaseOS E4S (v.8.8), Red Hat Enterprise Linux BaseOS TUS (v.8.8)"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-05-04T19:01:26.972Z",
                "value": "Reported to Red Hat."
              },
              {
                "lang": "en",
                "time": "2026-05-04T18:10:10.509Z",
                "value": "Made public."
              }
            ],
            "title": "postfix: buffer over-read via malformed enhanced status code",
            "workarounds": [
              {
                "lang": "en",
                "value": "To mitigate this vulnerability, review and adjust the following Postfix configurations:\n\n- DNSBL: Remove the $rbl_text variable from the rbl_reply_maps and default_rbl_reply settings to prevent triggers via malicious DNSBL TXT responses.\n- Policy Servers and Milters: Ensure any connected policy daemons or milters return fully RFC-compliant enhanced status codes. They must not return codes that lack text after the third digit (e.g., they should return 5.7.1 Rejected rather than just 5.7.1).\n- Access Tables and Content Checks: Audit custom access tables, header_checks, body_checks, and transport_maps (specifically error transports) to confirm that any manually defined rejection messages or status codes include descriptive text following the numeric code."
              }
            ],
            "x_adpType": "supplier",
            "x_generator": {
              "engine": "sadp-cli 1.0.0"
            }
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Postfix",
              "vendor": "Postfix",
              "versions": [
                {
                  "lessThan": "3.8.16",
                  "status": "affected",
                  "version": "2.3",
                  "versionType": "custom"
                },
                {
                  "lessThan": "3.9.10",
                  "status": "affected",
                  "version": "3.9",
                  "versionType": "custom"
                },
                {
                  "lessThan": "3.10.9",
                  "status": "affected",
                  "version": "3.10",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.8.16",
                      "versionStartIncluding": "2.3",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.9.10",
                      "versionStartIncluding": "3.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.10.9",
                      "versionStartIncluding": "3.10",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-193",
                  "description": "CWE-193 Off-by-one Error",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-04T18:28:07.825Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://www.mail-archive.com/postfix-announce@postfix.org/msg00110.html"
            }
          ],
          "x_generator": {
            "engine": "CVE-Request-form 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2026-43964",
        "datePublished": "2026-05-04T18:10:10.509Z",
        "dateReserved": "2026-05-04T18:10:10.120Z",
        "dateUpdated": "2026-08-20T12:31:52.721Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-51764 (GCVE-0-2023-51764)

    Vulnerability from nvd – Published: 2023-12-24 00:00 – Updated: 2025-11-04 22:05
    VLAI
    Summary
    Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Postfix supports <LF>.<CR><LF> but some other popular e-mail servers do not. To prevent attack variants (by always disallowing <LF> without <CR>), a different solution is required, such as the smtpd_forbid_bare_newline=yes option with a Postfix minimum version of 3.5.23, 3.6.13, 3.7.9, 3.8.4, or 3.9.
    Severity
    No CVSS data available.
    CWE
    • n/a
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-04T22:05:26.900Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.postfix.org/smtp-smuggling.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/"
              },
              {
                "name": "[oss-security] 20231224 Re: Re: New SMTP smuggling attack",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2023/12/24/1"
              },
              {
                "name": "[oss-security] 20231225 Re: Re: New SMTP smuggling attack",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2023/12/25/1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2255563"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/security/cve/CVE-2023-51764"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11782.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/eeenvik1/CVE-2023-51764"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/duy-31/CVE-2023-51764"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.youtube.com/watch?v=V8KPV96g1To"
              },
              {
                "name": "FEDORA-2024-c839e7294f",
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QRLF5SOS7TP5N7FQSEK2NFNB44ISVTZC/"
              },
              {
                "name": "FEDORA-2024-5c186175f2",
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JQ5WXFCW2N6G2PH3JXDTYW5PH5EBQEGO/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lwn.net/Articles/956533/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.openwall.com/lists/oss-security/2024/01/22/1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.postfix.org/announcements/postfix-3.8.5.html"
              },
              {
                "name": "[debian-lts-announce] 20240130 [SECURITY] [DLA 3725-1] postfix security update",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00020.html"
              },
              {
                "name": "[oss-security] 20240508 Re: New SMTP smuggling attack",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/05/09/3"
              },
              {
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QRLF5SOS7TP5N7FQSEK2NFNB44ISVTZC/"
              },
              {
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JQ5WXFCW2N6G2PH3JXDTYW5PH5EBQEGO/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Postfix supports \u003cLF\u003e.\u003cCR\u003e\u003cLF\u003e but some other popular e-mail servers do not. To prevent attack variants (by always disallowing \u003cLF\u003e without \u003cCR\u003e), a different solution is required, such as the smtpd_forbid_bare_newline=yes option with a Postfix minimum version of 3.5.23, 3.6.13, 3.7.9, 3.8.4, or 3.9."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-10T18:07:59.991Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://www.postfix.org/smtp-smuggling.html"
            },
            {
              "url": "https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/"
            },
            {
              "name": "[oss-security] 20231224 Re: Re: New SMTP smuggling attack",
              "tags": [
                "mailing-list"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2023/12/24/1"
            },
            {
              "name": "[oss-security] 20231225 Re: Re: New SMTP smuggling attack",
              "tags": [
                "mailing-list"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2023/12/25/1"
            },
            {
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2255563"
            },
            {
              "url": "https://access.redhat.com/security/cve/CVE-2023-51764"
            },
            {
              "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11782.html"
            },
            {
              "url": "https://github.com/eeenvik1/CVE-2023-51764"
            },
            {
              "url": "https://github.com/duy-31/CVE-2023-51764"
            },
            {
              "url": "https://www.youtube.com/watch?v=V8KPV96g1To"
            },
            {
              "name": "FEDORA-2024-c839e7294f",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QRLF5SOS7TP5N7FQSEK2NFNB44ISVTZC/"
            },
            {
              "name": "FEDORA-2024-5c186175f2",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JQ5WXFCW2N6G2PH3JXDTYW5PH5EBQEGO/"
            },
            {
              "url": "https://lwn.net/Articles/956533/"
            },
            {
              "url": "https://www.openwall.com/lists/oss-security/2024/01/22/1"
            },
            {
              "url": "https://www.postfix.org/announcements/postfix-3.8.5.html"
            },
            {
              "name": "[debian-lts-announce] 20240130 [SECURITY] [DLA 3725-1] postfix security update",
              "tags": [
                "mailing-list"
              ],
              "url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00020.html"
            },
            {
              "name": "[oss-security] 20240508 Re: New SMTP smuggling attack",
              "tags": [
                "mailing-list"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2024/05/09/3"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2023-51764",
        "datePublished": "2023-12-24T00:00:00.000Z",
        "dateReserved": "2023-12-24T00:00:00.000Z",
        "dateUpdated": "2025-11-04T22:05:26.900Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2020-12063 (GCVE-0-2020-12063)

    Vulnerability from nvd – Published: 2020-04-24 11:59 – Updated: 2024-08-04 11:48 Disputed
    VLAI
    Summary
    A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demonstrated by the similarity of \xce\xbf to the 'o' character. This is potentially relevant when the /etc/postfix/sender_login feature is used, because a spoofed outbound message that uses a configured sender address is blocked with a "Sender address rejected: not logged in" error message, but a spoofed outbound message that uses a homoglyph of a configured sender address is not blocked. NOTE: some third parties argue that any missed blocking of spoofed outbound messages - except for exact matches to a sender address in the /etc/postfix/sender_login file - is outside the design goals of Postfix and thus cannot be considered a Postfix vulnerability
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T11:48:57.775Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.openwall.com/lists/oss-security/2020/04/23/3"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.openwall.com/lists/oss-security/2020/04/23/12"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demonstrated by the similarity of \\xce\\xbf to the \u0027o\u0027 character. This is potentially relevant when the /etc/postfix/sender_login feature is used, because a spoofed outbound message that uses a configured sender address is blocked with a \"Sender address rejected: not logged in\" error message, but a spoofed outbound message that uses a homoglyph of a configured sender address is not blocked. NOTE: some third parties argue that any missed blocking of spoofed outbound messages - except for exact matches to a sender address in the /etc/postfix/sender_login file - is outside the design goals of Postfix and thus cannot be considered a Postfix vulnerability"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-04-24T12:05:42.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.openwall.com/lists/oss-security/2020/04/23/3"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.openwall.com/lists/oss-security/2020/04/23/12"
            }
          ],
          "tags": [
            "disputed"
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2020-12063",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "** DISPUTED ** A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demonstrated by the similarity of \\xce\\xbf to the \u0027o\u0027 character. This is potentially relevant when the /etc/postfix/sender_login feature is used, because a spoofed outbound message that uses a configured sender address is blocked with a \"Sender address rejected: not logged in\" error message, but a spoofed outbound message that uses a homoglyph of a configured sender address is not blocked. NOTE: some third parties argue that any missed blocking of spoofed outbound messages - except for exact matches to a sender address in the /etc/postfix/sender_login file - is outside the design goals of Postfix and thus cannot be considered a Postfix vulnerability."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://www.openwall.com/lists/oss-security/2020/04/23/3",
                  "refsource": "MISC",
                  "url": "https://www.openwall.com/lists/oss-security/2020/04/23/3"
                },
                {
                  "name": "https://www.openwall.com/lists/oss-security/2020/04/23/12",
                  "refsource": "MISC",
                  "url": "https://www.openwall.com/lists/oss-security/2020/04/23/12"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2020-12063",
        "datePublished": "2020-04-24T11:59:03.000Z",
        "dateReserved": "2020-04-22T00:00:00.000Z",
        "dateUpdated": "2024-08-04T11:48:57.775Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2017-10140 (GCVE-0-2017-10140)

    Vulnerability from nvd – Published: 2018-04-16 16:00 – Updated: 2024-08-05 17:33
    VLAI
    Summary
    Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Date Public
    2017-06-11 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T17:33:16.056Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "[oss-sec] 20170611 Berkeley DB reads DB_CONFIG from cwd",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://seclists.org/oss-sec/2017/q3/285"
              },
              {
                "name": "RHSA-2019:0366",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2019:0366"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.oracle.com/security-alerts/cpujul2020.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.postfix.org/announcements/postfix-3.2.2.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2017-06-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-07-15T17:34:25.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "[oss-sec] 20170611 Berkeley DB reads DB_CONFIG from cwd",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://seclists.org/oss-sec/2017/q3/285"
            },
            {
              "name": "RHSA-2019:0366",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2019:0366"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.oracle.com/security-alerts/cpujul2020.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.postfix.org/announcements/postfix-3.2.2.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2017-10140",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "[oss-sec] 20170611 Berkeley DB reads DB_CONFIG from cwd",
                  "refsource": "MLIST",
                  "url": "http://seclists.org/oss-sec/2017/q3/285"
                },
                {
                  "name": "RHSA-2019:0366",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2019:0366"
                },
                {
                  "name": "https://www.oracle.com/security-alerts/cpujul2020.html",
                  "refsource": "MISC",
                  "url": "https://www.oracle.com/security-alerts/cpujul2020.html"
                },
                {
                  "name": "http://www.postfix.org/announcements/postfix-3.2.2.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.postfix.org/announcements/postfix-3.2.2.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2017-10140",
        "datePublished": "2018-04-16T16:00:00.000Z",
        "dateReserved": "2017-06-21T00:00:00.000Z",
        "dateUpdated": "2024-08-05T17:33:16.056Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2012-0811 (GCVE-0-2012-0811)

    Vulnerability from nvd – Published: 2014-10-01 14:00 – Updated: 2024-08-06 18:38
    VLAI
    Summary
    Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the pw parameter to the pacrypt function, when mysql_encrypt is configured, or (2) unspecified vectors that are used in backup files generated by backup.php.
    Severity
    No CVSS data available.
    CWE
    • n/a
    Date Public
    2012-01-26 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T18:38:14.403Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "51680",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/51680"
              },
              {
                "name": "[oss-security] 20120126 CVE request: PostfixAdmin SQL injections and XSS",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2012/01/26/5"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://www.codseq.it/advisories/multiple_vulnerabilities_in_postfixadmin"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3/CHANGELOG.TXT"
              },
              {
                "name": "[oss-security] 20120127 Re: CVE request: PostfixAdmin SQL injections and XSS",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2012/01/27/5"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2012-01-26T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the pw parameter to the pacrypt function, when mysql_encrypt is configured, or (2) unspecified vectors that are used in backup files generated by backup.php."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2014-10-01T13:57:00.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "name": "51680",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/51680"
            },
            {
              "name": "[oss-security] 20120126 CVE request: PostfixAdmin SQL injections and XSS",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2012/01/26/5"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://www.codseq.it/advisories/multiple_vulnerabilities_in_postfixadmin"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3/CHANGELOG.TXT"
            },
            {
              "name": "[oss-security] 20120127 Re: CVE request: PostfixAdmin SQL injections and XSS",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2012/01/27/5"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secalert@redhat.com",
              "ID": "CVE-2012-0811",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the pw parameter to the pacrypt function, when mysql_encrypt is configured, or (2) unspecified vectors that are used in backup files generated by backup.php."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "51680",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/51680"
                },
                {
                  "name": "[oss-security] 20120126 CVE request: PostfixAdmin SQL injections and XSS",
                  "refsource": "MLIST",
                  "url": "http://www.openwall.com/lists/oss-security/2012/01/26/5"
                },
                {
                  "name": "http://www.codseq.it/advisories/multiple_vulnerabilities_in_postfixadmin",
                  "refsource": "MISC",
                  "url": "http://www.codseq.it/advisories/multiple_vulnerabilities_in_postfixadmin"
                },
                {
                  "name": "https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3/CHANGELOG.TXT",
                  "refsource": "CONFIRM",
                  "url": "https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3/CHANGELOG.TXT"
                },
                {
                  "name": "[oss-security] 20120127 Re: CVE request: PostfixAdmin SQL injections and XSS",
                  "refsource": "MLIST",
                  "url": "http://www.openwall.com/lists/oss-security/2012/01/27/5"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2012-0811",
        "datePublished": "2014-10-01T14:00:00.000Z",
        "dateReserved": "2012-01-19T00:00:00.000Z",
        "dateUpdated": "2024-08-06T18:38:14.403Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2011-1720 (GCVE-0-2011-1720)

    Vulnerability from nvd – Published: 2011-05-13 17:00 – Updated: 2024-08-06 22:37
    VLAI
    Summary
    The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.securityfocus.com/archive/1/517917/100… mailing-listx_refsource_BUGTRAQ
    http://www.postfix.org/CVE-2011-1720.html x_refsource_CONFIRM
    http://secunia.com/advisories/44500 third-party-advisoryx_refsource_SECUNIA
    http://www.securityfocus.com/bid/47778 vdb-entryx_refsource_BID
    http://security.gentoo.org/glsa/glsa-201206-33.xml vendor-advisoryx_refsource_GENTOO
    http://www.osvdb.org/72259 vdb-entryx_refsource_OSVDB
    http://www.kb.cert.org/vuls/id/727230 third-party-advisoryx_refsource_CERT-VN
    http://www.securitytracker.com/id?1025521 vdb-entryx_refsource_SECTRACK
    http://www.mail-archive.com/postfix-announce%40po… mailing-listx_refsource_MLIST
    http://www.postfix.org/announcements/postfix-2.8.3.html x_refsource_CONFIRM
    http://securityreason.com/securityalert/8247 third-party-advisoryx_refsource_SREASON
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    https://bugzilla.redhat.com/show_bug.cgi?id=699035 x_refsource_CONFIRM
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://kb.juniper.net/InfoCenter/index?page=conte… x_refsource_CONFIRM
    http://www.debian.org/security/2011/dsa-2233 vendor-advisoryx_refsource_DEBIAN
    http://www.ubuntu.com/usn/usn-1131-1 vendor-advisoryx_refsource_UBUNTU
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    Date Public
    2011-05-09 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T22:37:25.642Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "20110509 Memory corruption in Postfix SMTP server Cyrus SASL support (CVE-2011-1720)",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/517917/100/0/threaded"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.postfix.org/CVE-2011-1720.html"
              },
              {
                "name": "44500",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/44500"
              },
              {
                "name": "47778",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/47778"
              },
              {
                "name": "GLSA-201206-33",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-201206-33.xml"
              },
              {
                "name": "72259",
                "tags": [
                  "vdb-entry",
                  "x_refsource_OSVDB",
                  "x_transferred"
                ],
                "url": "http://www.osvdb.org/72259"
              },
              {
                "name": "VU#727230",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT-VN",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/727230"
              },
              {
                "name": "1025521",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1025521"
              },
              {
                "name": "[postfix-announce] 20110509 Memory corruption in Postfix SMTP server Cyrus SASL support (CVE-2011-1720)",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.mail-archive.com/postfix-announce%40postfix.org/msg00007.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.postfix.org/announcements/postfix-2.8.3.html"
              },
              {
                "name": "8247",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SREASON",
                  "x_transferred"
                ],
                "url": "http://securityreason.com/securityalert/8247"
              },
              {
                "name": "SUSE-SA:2011:023",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00002.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=699035"
              },
              {
                "name": "MDVSA-2011:090",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2011:090"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10705"
              },
              {
                "name": "DSA-2233",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2011/dsa-2233"
              },
              {
                "name": "USN-1131-1",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://www.ubuntu.com/usn/usn-1131-1"
              },
              {
                "name": "postfix-cyrus-sasl-code-exec(67359)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67359"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2011-05-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-10-09T18:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "20110509 Memory corruption in Postfix SMTP server Cyrus SASL support (CVE-2011-1720)",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://www.securityfocus.com/archive/1/517917/100/0/threaded"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.postfix.org/CVE-2011-1720.html"
            },
            {
              "name": "44500",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/44500"
            },
            {
              "name": "47778",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/47778"
            },
            {
              "name": "GLSA-201206-33",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-201206-33.xml"
            },
            {
              "name": "72259",
              "tags": [
                "vdb-entry",
                "x_refsource_OSVDB"
              ],
              "url": "http://www.osvdb.org/72259"
            },
            {
              "name": "VU#727230",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT-VN"
              ],
              "url": "http://www.kb.cert.org/vuls/id/727230"
            },
            {
              "name": "1025521",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1025521"
            },
            {
              "name": "[postfix-announce] 20110509 Memory corruption in Postfix SMTP server Cyrus SASL support (CVE-2011-1720)",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.mail-archive.com/postfix-announce%40postfix.org/msg00007.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.postfix.org/announcements/postfix-2.8.3.html"
            },
            {
              "name": "8247",
              "tags": [
                "third-party-advisory",
                "x_refsource_SREASON"
              ],
              "url": "http://securityreason.com/securityalert/8247"
            },
            {
              "name": "SUSE-SA:2011:023",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00002.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=699035"
            },
            {
              "name": "MDVSA-2011:090",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2011:090"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10705"
            },
            {
              "name": "DSA-2233",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2011/dsa-2233"
            },
            {
              "name": "USN-1131-1",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://www.ubuntu.com/usn/usn-1131-1"
            },
            {
              "name": "postfix-cyrus-sasl-code-exec(67359)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67359"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2011-1720",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "20110509 Memory corruption in Postfix SMTP server Cyrus SASL support (CVE-2011-1720)",
                  "refsource": "BUGTRAQ",
                  "url": "http://www.securityfocus.com/archive/1/517917/100/0/threaded"
                },
                {
                  "name": "http://www.postfix.org/CVE-2011-1720.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.postfix.org/CVE-2011-1720.html"
                },
                {
                  "name": "44500",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/44500"
                },
                {
                  "name": "47778",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/47778"
                },
                {
                  "name": "GLSA-201206-33",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-201206-33.xml"
                },
                {
                  "name": "72259",
                  "refsource": "OSVDB",
                  "url": "http://www.osvdb.org/72259"
                },
                {
                  "name": "VU#727230",
                  "refsource": "CERT-VN",
                  "url": "http://www.kb.cert.org/vuls/id/727230"
                },
                {
                  "name": "1025521",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1025521"
                },
                {
                  "name": "[postfix-announce] 20110509 Memory corruption in Postfix SMTP server Cyrus SASL support (CVE-2011-1720)",
                  "refsource": "MLIST",
                  "url": "http://www.mail-archive.com/postfix-announce@postfix.org/msg00007.html"
                },
                {
                  "name": "http://www.postfix.org/announcements/postfix-2.8.3.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.postfix.org/announcements/postfix-2.8.3.html"
                },
                {
                  "name": "8247",
                  "refsource": "SREASON",
                  "url": "http://securityreason.com/securityalert/8247"
                },
                {
                  "name": "SUSE-SA:2011:023",
                  "refsource": "SUSE",
                  "url": "http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00002.html"
                },
                {
                  "name": "https://bugzilla.redhat.com/show_bug.cgi?id=699035",
                  "refsource": "CONFIRM",
                  "url": "https://bugzilla.redhat.com/show_bug.cgi?id=699035"
                },
                {
                  "name": "MDVSA-2011:090",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2011:090"
                },
                {
                  "name": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10705",
                  "refsource": "CONFIRM",
                  "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10705"
                },
                {
                  "name": "DSA-2233",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2011/dsa-2233"
                },
                {
                  "name": "USN-1131-1",
                  "refsource": "UBUNTU",
                  "url": "http://www.ubuntu.com/usn/usn-1131-1"
                },
                {
                  "name": "postfix-cyrus-sasl-code-exec(67359)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67359"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2011-1720",
        "datePublished": "2011-05-13T17:00:00.000Z",
        "dateReserved": "2011-04-18T00:00:00.000Z",
        "dateUpdated": "2024-08-06T22:37:25.642Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2011-0411 (GCVE-0-2011-0411)

    Vulnerability from nvd – Published: 2011-03-16 22:00 – Updated: 2024-08-06 21:51
    VLAI
    Summary
    The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.oracle.com/technetwork/topics/security… x_refsource_CONFIRM
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    http://www.postfix.org/CVE-2011-0411.html x_refsource_CONFIRM
    http://secunia.com/advisories/43646 third-party-advisoryx_refsource_SECUNIA
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    http://www.osvdb.org/71021 vdb-entryx_refsource_OSVDB
    http://www.vupen.com/english/advisories/2011/0752 vdb-entryx_refsource_VUPEN
    http://www.vupen.com/english/advisories/2011/0891 vdb-entryx_refsource_VUPEN
    http://security.gentoo.org/glsa/glsa-201206-33.xml vendor-advisoryx_refsource_GENTOO
    http://lists.fedoraproject.org/pipermail/package-… vendor-advisoryx_refsource_FEDORA
    http://secunia.com/advisories/43874 third-party-advisoryx_refsource_SECUNIA
    http://lists.fedoraproject.org/pipermail/package-… vendor-advisoryx_refsource_FEDORA
    http://www.kb.cert.org/vuls/id/MORO-8ELH6Z x_refsource_CONFIRM
    http://lists.apple.com/archives/Security-announce… vendor-advisoryx_refsource_APPLE
    http://www.vupen.com/english/advisories/2011/0611 vdb-entryx_refsource_VUPEN
    http://www.securityfocus.com/bid/46767 vdb-entryx_refsource_BID
    http://www.redhat.com/support/errata/RHSA-2011-04… vendor-advisoryx_refsource_REDHAT
    http://www.kb.cert.org/vuls/id/555316 third-party-advisoryx_refsource_CERT-VN
    http://securitytracker.com/id?1025179 vdb-entryx_refsource_SECTRACK
    http://www.redhat.com/support/errata/RHSA-2011-04… vendor-advisoryx_refsource_REDHAT
    http://support.apple.com/kb/HT5002 x_refsource_CONFIRM
    http://kb.juniper.net/InfoCenter/index?page=conte… x_refsource_CONFIRM
    http://www.debian.org/security/2011/dsa-2233 vendor-advisoryx_refsource_DEBIAN
    http://www.openwall.com/lists/oss-security/2021/08/10/2 mailing-listx_refsource_MLIST
    Date Public
    2011-03-03 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T21:51:08.944Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html"
              },
              {
                "name": "multiple-starttls-command-execution(65932)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/65932"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.postfix.org/CVE-2011-0411.html"
              },
              {
                "name": "43646",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/43646"
              },
              {
                "name": "SUSE-SR:2011:009",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html"
              },
              {
                "name": "71021",
                "tags": [
                  "vdb-entry",
                  "x_refsource_OSVDB",
                  "x_transferred"
                ],
                "url": "http://www.osvdb.org/71021"
              },
              {
                "name": "ADV-2011-0752",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0752"
              },
              {
                "name": "ADV-2011-0891",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0891"
              },
              {
                "name": "GLSA-201206-33",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-201206-33.xml"
              },
              {
                "name": "FEDORA-2011-3355",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056560.html"
              },
              {
                "name": "43874",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/43874"
              },
              {
                "name": "FEDORA-2011-3394",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056559.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/MORO-8ELH6Z"
              },
              {
                "name": "APPLE-SA-2011-10-12-3",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_APPLE",
                  "x_transferred"
                ],
                "url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html"
              },
              {
                "name": "ADV-2011-0611",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0611"
              },
              {
                "name": "46767",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/46767"
              },
              {
                "name": "RHSA-2011:0423",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2011-0423.html"
              },
              {
                "name": "VU#555316",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT-VN",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/555316"
              },
              {
                "name": "1025179",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://securitytracker.com/id?1025179"
              },
              {
                "name": "RHSA-2011:0422",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2011-0422.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://support.apple.com/kb/HT5002"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10705"
              },
              {
                "name": "DSA-2233",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2011/dsa-2233"
              },
              {
                "name": "[oss-security] 20210810 STARTTLS vulnerabilities",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2021/08/10/2"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2011-03-03T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a \"plaintext command injection\" attack."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-08-10T11:07:06.000Z",
            "orgId": "37e5125f-f79b-445b-8fad-9564f167944b",
            "shortName": "certcc"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html"
            },
            {
              "name": "multiple-starttls-command-execution(65932)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/65932"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.postfix.org/CVE-2011-0411.html"
            },
            {
              "name": "43646",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/43646"
            },
            {
              "name": "SUSE-SR:2011:009",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html"
            },
            {
              "name": "71021",
              "tags": [
                "vdb-entry",
                "x_refsource_OSVDB"
              ],
              "url": "http://www.osvdb.org/71021"
            },
            {
              "name": "ADV-2011-0752",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0752"
            },
            {
              "name": "ADV-2011-0891",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0891"
            },
            {
              "name": "GLSA-201206-33",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-201206-33.xml"
            },
            {
              "name": "FEDORA-2011-3355",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056560.html"
            },
            {
              "name": "43874",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/43874"
            },
            {
              "name": "FEDORA-2011-3394",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056559.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.kb.cert.org/vuls/id/MORO-8ELH6Z"
            },
            {
              "name": "APPLE-SA-2011-10-12-3",
              "tags": [
                "vendor-advisory",
                "x_refsource_APPLE"
              ],
              "url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html"
            },
            {
              "name": "ADV-2011-0611",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0611"
            },
            {
              "name": "46767",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/46767"
            },
            {
              "name": "RHSA-2011:0423",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2011-0423.html"
            },
            {
              "name": "VU#555316",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT-VN"
              ],
              "url": "http://www.kb.cert.org/vuls/id/555316"
            },
            {
              "name": "1025179",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://securitytracker.com/id?1025179"
            },
            {
              "name": "RHSA-2011:0422",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2011-0422.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://support.apple.com/kb/HT5002"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10705"
            },
            {
              "name": "DSA-2233",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2011/dsa-2233"
            },
            {
              "name": "[oss-security] 20210810 STARTTLS vulnerabilities",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2021/08/10/2"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cert@cert.org",
              "ID": "CVE-2011-0411",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a \"plaintext command injection\" attack."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html"
                },
                {
                  "name": "multiple-starttls-command-execution(65932)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/65932"
                },
                {
                  "name": "http://www.postfix.org/CVE-2011-0411.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.postfix.org/CVE-2011-0411.html"
                },
                {
                  "name": "43646",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/43646"
                },
                {
                  "name": "SUSE-SR:2011:009",
                  "refsource": "SUSE",
                  "url": "http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html"
                },
                {
                  "name": "71021",
                  "refsource": "OSVDB",
                  "url": "http://www.osvdb.org/71021"
                },
                {
                  "name": "ADV-2011-0752",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2011/0752"
                },
                {
                  "name": "ADV-2011-0891",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2011/0891"
                },
                {
                  "name": "GLSA-201206-33",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-201206-33.xml"
                },
                {
                  "name": "FEDORA-2011-3355",
                  "refsource": "FEDORA",
                  "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056560.html"
                },
                {
                  "name": "43874",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/43874"
                },
                {
                  "name": "FEDORA-2011-3394",
                  "refsource": "FEDORA",
                  "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056559.html"
                },
                {
                  "name": "http://www.kb.cert.org/vuls/id/MORO-8ELH6Z",
                  "refsource": "CONFIRM",
                  "url": "http://www.kb.cert.org/vuls/id/MORO-8ELH6Z"
                },
                {
                  "name": "APPLE-SA-2011-10-12-3",
                  "refsource": "APPLE",
                  "url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html"
                },
                {
                  "name": "ADV-2011-0611",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2011/0611"
                },
                {
                  "name": "46767",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/46767"
                },
                {
                  "name": "RHSA-2011:0423",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2011-0423.html"
                },
                {
                  "name": "VU#555316",
                  "refsource": "CERT-VN",
                  "url": "http://www.kb.cert.org/vuls/id/555316"
                },
                {
                  "name": "1025179",
                  "refsource": "SECTRACK",
                  "url": "http://securitytracker.com/id?1025179"
                },
                {
                  "name": "RHSA-2011:0422",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2011-0422.html"
                },
                {
                  "name": "http://support.apple.com/kb/HT5002",
                  "refsource": "CONFIRM",
                  "url": "http://support.apple.com/kb/HT5002"
                },
                {
                  "name": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10705",
                  "refsource": "CONFIRM",
                  "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10705"
                },
                {
                  "name": "DSA-2233",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2011/dsa-2233"
                },
                {
                  "name": "[oss-security] 20210810 STARTTLS vulnerabilities",
                  "refsource": "MLIST",
                  "url": "http://www.openwall.com/lists/oss-security/2021/08/10/2"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
        "assignerShortName": "certcc",
        "cveId": "CVE-2011-0411",
        "datePublished": "2011-03-16T22:00:00.000Z",
        "dateReserved": "2011-01-11T00:00:00.000Z",
        "dateUpdated": "2024-08-06T21:51:08.944Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2009-2939 (GCVE-0-2009-2939)

    Vulnerability from nvd – Published: 2009-09-21 19:00 – Updated: 2024-08-07 06:07
    VLAI
    Summary
    The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.openwall.com/lists/oss-security/2009/09/18/6 mailing-listx_refsource_MLIST
    http://www.debian.org/security/2011/dsa-2233 vendor-advisoryx_refsource_DEBIAN
    Date Public
    2009-09-18 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T06:07:37.330Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "[oss-security] 20090918 Insecure pid directory permissions for postfix on Debian / Ubuntu",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2009/09/18/6"
              },
              {
                "name": "DSA-2233",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2011/dsa-2233"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2009-09-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2011-08-23T09:00:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "[oss-security] 20090918 Insecure pid directory permissions for postfix on Debian / Ubuntu",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2009/09/18/6"
            },
            {
              "name": "DSA-2233",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2011/dsa-2233"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2009-2939",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "[oss-security] 20090918 Insecure pid directory permissions for postfix on Debian / Ubuntu",
                  "refsource": "MLIST",
                  "url": "http://www.openwall.com/lists/oss-security/2009/09/18/6"
                },
                {
                  "name": "DSA-2233",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2011/dsa-2233"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2009-2939",
        "datePublished": "2009-09-21T19:00:00.000Z",
        "dateReserved": "2009-08-23T00:00:00.000Z",
        "dateUpdated": "2024-08-07T06:07:37.330Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2026-43964 (GCVE-0-2026-43964)

    Vulnerability from cvelistv5 – Published: 2026-05-04 18:10 – Updated: 2026-08-20 12:31
    VLAI
    Summary
    Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-04 19:49 UTC
    CWE
    Impacted products
    Vendor Product Version
    Postfix Postfix Affected: 2.3 , < 3.8.16 (custom)
    Affected: 3.9 , < 3.9.10 (custom)
    Affected: 3.10 , < 3.10.9 (custom)
        cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*
        cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*
        cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 10 Unaffected: 2:3.8.5-10.el10_2 , < * (rpm)
        cpe:/o:redhat:enterprise_linux:10.2
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support Unaffected: 2:3.8.5-8.el10_0.1 , < * (rpm)
        cpe:/o:redhat:enterprise_linux_eus:10.0
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support Unaffected: 2:2.10.1-9.el7_9.1 , < * (rpm)
        cpe:/o:redhat:rhel_els:7
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 8 Unaffected: 2:3.5.8-8.el8_10 , < * (rpm)
        cpe:/a:redhat:enterprise_linux:8
        cpe:/o:redhat:enterprise_linux:8
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Unaffected: 2:3.5.8-1.el8_4.1 , < * (rpm)
        cpe:/a:redhat:rhel_aus:8.4
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Unaffected: 2:3.5.8-1.el8_4.1 , < * (rpm)
        cpe:/a:redhat:rhel_eus_long_life:8.4
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Unaffected: 2:3.5.8-4.el8_6.1 , < * (rpm)
        cpe:/a:redhat:rhel_aus:8.6
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Unaffected: 2:3.5.8-4.el8_6.1 , < * (rpm)
        cpe:/a:redhat:rhel_eus_long_life:8.6
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service Unaffected: 2:3.5.8-4.el8_8.1 , < * (rpm)
        cpe:/a:redhat:rhel_tus:8.8
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Unaffected: 2:3.5.8-4.el8_8.1 , < * (rpm)
        cpe:/a:redhat:rhel_e4s:8.8
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 9 Unaffected: 2:3.5.25-3.el9_8 , < * (rpm)
        cpe:/a:redhat:enterprise_linux:9
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 6     cpe:/o:redhat:enterprise_linux:6
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-43964",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-04T19:49:30.949584Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-04T19:49:41.165Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2026-05-04T22:21:13.917Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2026/05/04/30"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/o:redhat:enterprise_linux:10.2"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 10",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.8.5-10.el10_2",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/o:redhat:enterprise_linux_eus:10.0"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 10.0 Extended Update Support",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.8.5-8.el10_0.1",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/o:redhat:rhel_els:7"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:2.10.1-9.el7_9.1",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:enterprise_linux:8",
                  "cpe:/o:redhat:enterprise_linux:8"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 8",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.5.8-8.el8_10",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:rhel_aus:8.4"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.5.8-1.el8_4.1",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:rhel_eus_long_life:8.4"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.5.8-1.el8_4.1",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:rhel_aus:8.6"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.5.8-4.el8_6.1",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:rhel_eus_long_life:8.6"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.5.8-4.el8_6.1",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:rhel_tus:8.8"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.5.8-4.el8_8.1",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:rhel_e4s:8.8"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.5.8-4.el8_8.1",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:enterprise_linux:9"
                ],
                "defaultStatus": "affected",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 9",
                "vendor": "Red Hat",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "2:3.5.25-3.el9_8",
                    "versionType": "rpm"
                  }
                ]
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/o:redhat:enterprise_linux:6"
                ],
                "defaultStatus": "unknown",
                "packageName": "postfix",
                "product": "Red Hat Enterprise Linux 6",
                "vendor": "Red Hat"
              }
            ],
            "datePublic": "2026-05-04T18:10:10.509Z",
            "descriptions": [
              {
                "lang": "en",
                "value": "A flaw was found in Postfix. This issue occurs when processing enhanced status codes, specifically an enhanced status code that lacks text following the third number. Depending on the configuration of the server, this allows a remote attacker to cause a buffer over-read of only 1 byte, leading to an application crash and resulting in a denial of service."
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "namespace": "https://access.redhat.com/security/updates/classification/",
                    "value": "Important"
                  },
                  "type": "Red Hat severity rating"
                }
              },
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                },
                "format": "CVSS"
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-193",
                    "description": "Off-by-one Error",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-20T12:31:52.721Z",
              "orgId": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "shortName": "redhat-SADP"
            },
            "references": [
              {
                "tags": [
                  "vdb-entry",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/security/cve/CVE-2026-43964"
              },
              {
                "name": "RHBZ#2466488",
                "tags": [
                  "issue-tracking",
                  "x_refsource_REDHAT"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466488"
              },
              {
                "tags": [
                  "x_sadp-csaf-vex"
                ],
                "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43964.json"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:57174"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:51436"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:25930"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:25932"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:26205"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:51034"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:50963"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:50964"
              }
            ],
            "solutions": [
              {
                "lang": "en",
                "value": "RHSA-2026:57174: Red Hat Enterprise Linux Server (v. 7 ELS)"
              },
              {
                "lang": "en",
                "value": "RHSA-2026:51436: Red Hat Enterprise Linux AppStream EUS (v. 10.0)"
              },
              {
                "lang": "en",
                "value": "RHSA-2026:25930: Red Hat Enterprise Linux AppStream (v. 10)"
              },
              {
                "lang": "en",
                "value": "RHSA-2026:25932: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux BaseOS (v. 8)"
              },
              {
                "lang": "en",
                "value": "RHSA-2026:26205: Red Hat Enterprise Linux AppStream (v. 9)"
              },
              {
                "lang": "en",
                "value": "RHSA-2026:51034: Red Hat Enterprise Linux BaseOS AUS (v.8.4), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)"
              },
              {
                "lang": "en",
                "value": "RHSA-2026:50963: Red Hat Enterprise Linux BaseOS AUS (v.8.6), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)"
              },
              {
                "lang": "en",
                "value": "RHSA-2026:50964: Red Hat Enterprise Linux BaseOS E4S (v.8.8), Red Hat Enterprise Linux BaseOS TUS (v.8.8)"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-05-04T19:01:26.972Z",
                "value": "Reported to Red Hat."
              },
              {
                "lang": "en",
                "time": "2026-05-04T18:10:10.509Z",
                "value": "Made public."
              }
            ],
            "title": "postfix: buffer over-read via malformed enhanced status code",
            "workarounds": [
              {
                "lang": "en",
                "value": "To mitigate this vulnerability, review and adjust the following Postfix configurations:\n\n- DNSBL: Remove the $rbl_text variable from the rbl_reply_maps and default_rbl_reply settings to prevent triggers via malicious DNSBL TXT responses.\n- Policy Servers and Milters: Ensure any connected policy daemons or milters return fully RFC-compliant enhanced status codes. They must not return codes that lack text after the third digit (e.g., they should return 5.7.1 Rejected rather than just 5.7.1).\n- Access Tables and Content Checks: Audit custom access tables, header_checks, body_checks, and transport_maps (specifically error transports) to confirm that any manually defined rejection messages or status codes include descriptive text following the numeric code."
              }
            ],
            "x_adpType": "supplier",
            "x_generator": {
              "engine": "sadp-cli 1.0.0"
            }
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Postfix",
              "vendor": "Postfix",
              "versions": [
                {
                  "lessThan": "3.8.16",
                  "status": "affected",
                  "version": "2.3",
                  "versionType": "custom"
                },
                {
                  "lessThan": "3.9.10",
                  "status": "affected",
                  "version": "3.9",
                  "versionType": "custom"
                },
                {
                  "lessThan": "3.10.9",
                  "status": "affected",
                  "version": "3.10",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.8.16",
                      "versionStartIncluding": "2.3",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.9.10",
                      "versionStartIncluding": "3.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.10.9",
                      "versionStartIncluding": "3.10",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-193",
                  "description": "CWE-193 Off-by-one Error",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-04T18:28:07.825Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://www.mail-archive.com/postfix-announce@postfix.org/msg00110.html"
            }
          ],
          "x_generator": {
            "engine": "CVE-Request-form 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2026-43964",
        "datePublished": "2026-05-04T18:10:10.509Z",
        "dateReserved": "2026-05-04T18:10:10.120Z",
        "dateUpdated": "2026-08-20T12:31:52.721Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-51764 (GCVE-0-2023-51764)

    Vulnerability from cvelistv5 – Published: 2023-12-24 00:00 – Updated: 2025-11-04 22:05
    VLAI
    Summary
    Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Postfix supports <LF>.<CR><LF> but some other popular e-mail servers do not. To prevent attack variants (by always disallowing <LF> without <CR>), a different solution is required, such as the smtpd_forbid_bare_newline=yes option with a Postfix minimum version of 3.5.23, 3.6.13, 3.7.9, 3.8.4, or 3.9.
    Severity
    No CVSS data available.
    CWE
    • n/a
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-04T22:05:26.900Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.postfix.org/smtp-smuggling.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/"
              },
              {
                "name": "[oss-security] 20231224 Re: Re: New SMTP smuggling attack",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2023/12/24/1"
              },
              {
                "name": "[oss-security] 20231225 Re: Re: New SMTP smuggling attack",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2023/12/25/1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2255563"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/security/cve/CVE-2023-51764"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11782.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/eeenvik1/CVE-2023-51764"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/duy-31/CVE-2023-51764"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.youtube.com/watch?v=V8KPV96g1To"
              },
              {
                "name": "FEDORA-2024-c839e7294f",
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QRLF5SOS7TP5N7FQSEK2NFNB44ISVTZC/"
              },
              {
                "name": "FEDORA-2024-5c186175f2",
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JQ5WXFCW2N6G2PH3JXDTYW5PH5EBQEGO/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lwn.net/Articles/956533/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.openwall.com/lists/oss-security/2024/01/22/1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.postfix.org/announcements/postfix-3.8.5.html"
              },
              {
                "name": "[debian-lts-announce] 20240130 [SECURITY] [DLA 3725-1] postfix security update",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00020.html"
              },
              {
                "name": "[oss-security] 20240508 Re: New SMTP smuggling attack",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/05/09/3"
              },
              {
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QRLF5SOS7TP5N7FQSEK2NFNB44ISVTZC/"
              },
              {
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JQ5WXFCW2N6G2PH3JXDTYW5PH5EBQEGO/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Postfix supports \u003cLF\u003e.\u003cCR\u003e\u003cLF\u003e but some other popular e-mail servers do not. To prevent attack variants (by always disallowing \u003cLF\u003e without \u003cCR\u003e), a different solution is required, such as the smtpd_forbid_bare_newline=yes option with a Postfix minimum version of 3.5.23, 3.6.13, 3.7.9, 3.8.4, or 3.9."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-10T18:07:59.991Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://www.postfix.org/smtp-smuggling.html"
            },
            {
              "url": "https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/"
            },
            {
              "name": "[oss-security] 20231224 Re: Re: New SMTP smuggling attack",
              "tags": [
                "mailing-list"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2023/12/24/1"
            },
            {
              "name": "[oss-security] 20231225 Re: Re: New SMTP smuggling attack",
              "tags": [
                "mailing-list"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2023/12/25/1"
            },
            {
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2255563"
            },
            {
              "url": "https://access.redhat.com/security/cve/CVE-2023-51764"
            },
            {
              "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11782.html"
            },
            {
              "url": "https://github.com/eeenvik1/CVE-2023-51764"
            },
            {
              "url": "https://github.com/duy-31/CVE-2023-51764"
            },
            {
              "url": "https://www.youtube.com/watch?v=V8KPV96g1To"
            },
            {
              "name": "FEDORA-2024-c839e7294f",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QRLF5SOS7TP5N7FQSEK2NFNB44ISVTZC/"
            },
            {
              "name": "FEDORA-2024-5c186175f2",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JQ5WXFCW2N6G2PH3JXDTYW5PH5EBQEGO/"
            },
            {
              "url": "https://lwn.net/Articles/956533/"
            },
            {
              "url": "https://www.openwall.com/lists/oss-security/2024/01/22/1"
            },
            {
              "url": "https://www.postfix.org/announcements/postfix-3.8.5.html"
            },
            {
              "name": "[debian-lts-announce] 20240130 [SECURITY] [DLA 3725-1] postfix security update",
              "tags": [
                "mailing-list"
              ],
              "url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00020.html"
            },
            {
              "name": "[oss-security] 20240508 Re: New SMTP smuggling attack",
              "tags": [
                "mailing-list"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2024/05/09/3"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2023-51764",
        "datePublished": "2023-12-24T00:00:00.000Z",
        "dateReserved": "2023-12-24T00:00:00.000Z",
        "dateUpdated": "2025-11-04T22:05:26.900Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2020-12063 (GCVE-0-2020-12063)

    Vulnerability from cvelistv5 – Published: 2020-04-24 11:59 – Updated: 2024-08-04 11:48 Disputed
    VLAI
    Summary
    A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demonstrated by the similarity of \xce\xbf to the 'o' character. This is potentially relevant when the /etc/postfix/sender_login feature is used, because a spoofed outbound message that uses a configured sender address is blocked with a "Sender address rejected: not logged in" error message, but a spoofed outbound message that uses a homoglyph of a configured sender address is not blocked. NOTE: some third parties argue that any missed blocking of spoofed outbound messages - except for exact matches to a sender address in the /etc/postfix/sender_login file - is outside the design goals of Postfix and thus cannot be considered a Postfix vulnerability
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T11:48:57.775Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.openwall.com/lists/oss-security/2020/04/23/3"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.openwall.com/lists/oss-security/2020/04/23/12"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demonstrated by the similarity of \\xce\\xbf to the \u0027o\u0027 character. This is potentially relevant when the /etc/postfix/sender_login feature is used, because a spoofed outbound message that uses a configured sender address is blocked with a \"Sender address rejected: not logged in\" error message, but a spoofed outbound message that uses a homoglyph of a configured sender address is not blocked. NOTE: some third parties argue that any missed blocking of spoofed outbound messages - except for exact matches to a sender address in the /etc/postfix/sender_login file - is outside the design goals of Postfix and thus cannot be considered a Postfix vulnerability"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-04-24T12:05:42.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.openwall.com/lists/oss-security/2020/04/23/3"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.openwall.com/lists/oss-security/2020/04/23/12"
            }
          ],
          "tags": [
            "disputed"
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2020-12063",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "** DISPUTED ** A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demonstrated by the similarity of \\xce\\xbf to the \u0027o\u0027 character. This is potentially relevant when the /etc/postfix/sender_login feature is used, because a spoofed outbound message that uses a configured sender address is blocked with a \"Sender address rejected: not logged in\" error message, but a spoofed outbound message that uses a homoglyph of a configured sender address is not blocked. NOTE: some third parties argue that any missed blocking of spoofed outbound messages - except for exact matches to a sender address in the /etc/postfix/sender_login file - is outside the design goals of Postfix and thus cannot be considered a Postfix vulnerability."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://www.openwall.com/lists/oss-security/2020/04/23/3",
                  "refsource": "MISC",
                  "url": "https://www.openwall.com/lists/oss-security/2020/04/23/3"
                },
                {
                  "name": "https://www.openwall.com/lists/oss-security/2020/04/23/12",
                  "refsource": "MISC",
                  "url": "https://www.openwall.com/lists/oss-security/2020/04/23/12"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2020-12063",
        "datePublished": "2020-04-24T11:59:03.000Z",
        "dateReserved": "2020-04-22T00:00:00.000Z",
        "dateUpdated": "2024-08-04T11:48:57.775Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2017-10140 (GCVE-0-2017-10140)

    Vulnerability from cvelistv5 – Published: 2018-04-16 16:00 – Updated: 2024-08-05 17:33
    VLAI
    Summary
    Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Date Public
    2017-06-11 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T17:33:16.056Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "[oss-sec] 20170611 Berkeley DB reads DB_CONFIG from cwd",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://seclists.org/oss-sec/2017/q3/285"
              },
              {
                "name": "RHSA-2019:0366",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2019:0366"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.oracle.com/security-alerts/cpujul2020.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.postfix.org/announcements/postfix-3.2.2.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2017-06-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-07-15T17:34:25.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "[oss-sec] 20170611 Berkeley DB reads DB_CONFIG from cwd",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://seclists.org/oss-sec/2017/q3/285"
            },
            {
              "name": "RHSA-2019:0366",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2019:0366"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.oracle.com/security-alerts/cpujul2020.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.postfix.org/announcements/postfix-3.2.2.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2017-10140",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "[oss-sec] 20170611 Berkeley DB reads DB_CONFIG from cwd",
                  "refsource": "MLIST",
                  "url": "http://seclists.org/oss-sec/2017/q3/285"
                },
                {
                  "name": "RHSA-2019:0366",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2019:0366"
                },
                {
                  "name": "https://www.oracle.com/security-alerts/cpujul2020.html",
                  "refsource": "MISC",
                  "url": "https://www.oracle.com/security-alerts/cpujul2020.html"
                },
                {
                  "name": "http://www.postfix.org/announcements/postfix-3.2.2.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.postfix.org/announcements/postfix-3.2.2.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2017-10140",
        "datePublished": "2018-04-16T16:00:00.000Z",
        "dateReserved": "2017-06-21T00:00:00.000Z",
        "dateUpdated": "2024-08-05T17:33:16.056Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2012-0811 (GCVE-0-2012-0811)

    Vulnerability from cvelistv5 – Published: 2014-10-01 14:00 – Updated: 2024-08-06 18:38
    VLAI
    Summary
    Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the pw parameter to the pacrypt function, when mysql_encrypt is configured, or (2) unspecified vectors that are used in backup files generated by backup.php.
    Severity
    No CVSS data available.
    CWE
    • n/a
    Date Public
    2012-01-26 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T18:38:14.403Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "51680",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/51680"
              },
              {
                "name": "[oss-security] 20120126 CVE request: PostfixAdmin SQL injections and XSS",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2012/01/26/5"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://www.codseq.it/advisories/multiple_vulnerabilities_in_postfixadmin"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3/CHANGELOG.TXT"
              },
              {
                "name": "[oss-security] 20120127 Re: CVE request: PostfixAdmin SQL injections and XSS",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2012/01/27/5"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2012-01-26T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the pw parameter to the pacrypt function, when mysql_encrypt is configured, or (2) unspecified vectors that are used in backup files generated by backup.php."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2014-10-01T13:57:00.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "name": "51680",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/51680"
            },
            {
              "name": "[oss-security] 20120126 CVE request: PostfixAdmin SQL injections and XSS",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2012/01/26/5"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://www.codseq.it/advisories/multiple_vulnerabilities_in_postfixadmin"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3/CHANGELOG.TXT"
            },
            {
              "name": "[oss-security] 20120127 Re: CVE request: PostfixAdmin SQL injections and XSS",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2012/01/27/5"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secalert@redhat.com",
              "ID": "CVE-2012-0811",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the pw parameter to the pacrypt function, when mysql_encrypt is configured, or (2) unspecified vectors that are used in backup files generated by backup.php."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "51680",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/51680"
                },
                {
                  "name": "[oss-security] 20120126 CVE request: PostfixAdmin SQL injections and XSS",
                  "refsource": "MLIST",
                  "url": "http://www.openwall.com/lists/oss-security/2012/01/26/5"
                },
                {
                  "name": "http://www.codseq.it/advisories/multiple_vulnerabilities_in_postfixadmin",
                  "refsource": "MISC",
                  "url": "http://www.codseq.it/advisories/multiple_vulnerabilities_in_postfixadmin"
                },
                {
                  "name": "https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3/CHANGELOG.TXT",
                  "refsource": "CONFIRM",
                  "url": "https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3/CHANGELOG.TXT"
                },
                {
                  "name": "[oss-security] 20120127 Re: CVE request: PostfixAdmin SQL injections and XSS",
                  "refsource": "MLIST",
                  "url": "http://www.openwall.com/lists/oss-security/2012/01/27/5"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2012-0811",
        "datePublished": "2014-10-01T14:00:00.000Z",
        "dateReserved": "2012-01-19T00:00:00.000Z",
        "dateUpdated": "2024-08-06T18:38:14.403Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2011-1720 (GCVE-0-2011-1720)

    Vulnerability from cvelistv5 – Published: 2011-05-13 17:00 – Updated: 2024-08-06 22:37
    VLAI
    Summary
    The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.securityfocus.com/archive/1/517917/100… mailing-listx_refsource_BUGTRAQ
    http://www.postfix.org/CVE-2011-1720.html x_refsource_CONFIRM
    http://secunia.com/advisories/44500 third-party-advisoryx_refsource_SECUNIA
    http://www.securityfocus.com/bid/47778 vdb-entryx_refsource_BID
    http://security.gentoo.org/glsa/glsa-201206-33.xml vendor-advisoryx_refsource_GENTOO
    http://www.osvdb.org/72259 vdb-entryx_refsource_OSVDB
    http://www.kb.cert.org/vuls/id/727230 third-party-advisoryx_refsource_CERT-VN
    http://www.securitytracker.com/id?1025521 vdb-entryx_refsource_SECTRACK
    http://www.mail-archive.com/postfix-announce%40po… mailing-listx_refsource_MLIST
    http://www.postfix.org/announcements/postfix-2.8.3.html x_refsource_CONFIRM
    http://securityreason.com/securityalert/8247 third-party-advisoryx_refsource_SREASON
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    https://bugzilla.redhat.com/show_bug.cgi?id=699035 x_refsource_CONFIRM
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://kb.juniper.net/InfoCenter/index?page=conte… x_refsource_CONFIRM
    http://www.debian.org/security/2011/dsa-2233 vendor-advisoryx_refsource_DEBIAN
    http://www.ubuntu.com/usn/usn-1131-1 vendor-advisoryx_refsource_UBUNTU
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    Date Public
    2011-05-09 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T22:37:25.642Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "20110509 Memory corruption in Postfix SMTP server Cyrus SASL support (CVE-2011-1720)",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/517917/100/0/threaded"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.postfix.org/CVE-2011-1720.html"
              },
              {
                "name": "44500",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/44500"
              },
              {
                "name": "47778",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/47778"
              },
              {
                "name": "GLSA-201206-33",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-201206-33.xml"
              },
              {
                "name": "72259",
                "tags": [
                  "vdb-entry",
                  "x_refsource_OSVDB",
                  "x_transferred"
                ],
                "url": "http://www.osvdb.org/72259"
              },
              {
                "name": "VU#727230",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT-VN",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/727230"
              },
              {
                "name": "1025521",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1025521"
              },
              {
                "name": "[postfix-announce] 20110509 Memory corruption in Postfix SMTP server Cyrus SASL support (CVE-2011-1720)",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.mail-archive.com/postfix-announce%40postfix.org/msg00007.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.postfix.org/announcements/postfix-2.8.3.html"
              },
              {
                "name": "8247",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SREASON",
                  "x_transferred"
                ],
                "url": "http://securityreason.com/securityalert/8247"
              },
              {
                "name": "SUSE-SA:2011:023",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00002.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=699035"
              },
              {
                "name": "MDVSA-2011:090",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2011:090"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10705"
              },
              {
                "name": "DSA-2233",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2011/dsa-2233"
              },
              {
                "name": "USN-1131-1",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://www.ubuntu.com/usn/usn-1131-1"
              },
              {
                "name": "postfix-cyrus-sasl-code-exec(67359)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67359"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2011-05-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-10-09T18:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "20110509 Memory corruption in Postfix SMTP server Cyrus SASL support (CVE-2011-1720)",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://www.securityfocus.com/archive/1/517917/100/0/threaded"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.postfix.org/CVE-2011-1720.html"
            },
            {
              "name": "44500",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/44500"
            },
            {
              "name": "47778",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/47778"
            },
            {
              "name": "GLSA-201206-33",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-201206-33.xml"
            },
            {
              "name": "72259",
              "tags": [
                "vdb-entry",
                "x_refsource_OSVDB"
              ],
              "url": "http://www.osvdb.org/72259"
            },
            {
              "name": "VU#727230",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT-VN"
              ],
              "url": "http://www.kb.cert.org/vuls/id/727230"
            },
            {
              "name": "1025521",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1025521"
            },
            {
              "name": "[postfix-announce] 20110509 Memory corruption in Postfix SMTP server Cyrus SASL support (CVE-2011-1720)",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.mail-archive.com/postfix-announce%40postfix.org/msg00007.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.postfix.org/announcements/postfix-2.8.3.html"
            },
            {
              "name": "8247",
              "tags": [
                "third-party-advisory",
                "x_refsource_SREASON"
              ],
              "url": "http://securityreason.com/securityalert/8247"
            },
            {
              "name": "SUSE-SA:2011:023",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00002.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=699035"
            },
            {
              "name": "MDVSA-2011:090",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2011:090"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10705"
            },
            {
              "name": "DSA-2233",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2011/dsa-2233"
            },
            {
              "name": "USN-1131-1",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://www.ubuntu.com/usn/usn-1131-1"
            },
            {
              "name": "postfix-cyrus-sasl-code-exec(67359)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67359"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2011-1720",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "20110509 Memory corruption in Postfix SMTP server Cyrus SASL support (CVE-2011-1720)",
                  "refsource": "BUGTRAQ",
                  "url": "http://www.securityfocus.com/archive/1/517917/100/0/threaded"
                },
                {
                  "name": "http://www.postfix.org/CVE-2011-1720.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.postfix.org/CVE-2011-1720.html"
                },
                {
                  "name": "44500",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/44500"
                },
                {
                  "name": "47778",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/47778"
                },
                {
                  "name": "GLSA-201206-33",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-201206-33.xml"
                },
                {
                  "name": "72259",
                  "refsource": "OSVDB",
                  "url": "http://www.osvdb.org/72259"
                },
                {
                  "name": "VU#727230",
                  "refsource": "CERT-VN",
                  "url": "http://www.kb.cert.org/vuls/id/727230"
                },
                {
                  "name": "1025521",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1025521"
                },
                {
                  "name": "[postfix-announce] 20110509 Memory corruption in Postfix SMTP server Cyrus SASL support (CVE-2011-1720)",
                  "refsource": "MLIST",
                  "url": "http://www.mail-archive.com/postfix-announce@postfix.org/msg00007.html"
                },
                {
                  "name": "http://www.postfix.org/announcements/postfix-2.8.3.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.postfix.org/announcements/postfix-2.8.3.html"
                },
                {
                  "name": "8247",
                  "refsource": "SREASON",
                  "url": "http://securityreason.com/securityalert/8247"
                },
                {
                  "name": "SUSE-SA:2011:023",
                  "refsource": "SUSE",
                  "url": "http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00002.html"
                },
                {
                  "name": "https://bugzilla.redhat.com/show_bug.cgi?id=699035",
                  "refsource": "CONFIRM",
                  "url": "https://bugzilla.redhat.com/show_bug.cgi?id=699035"
                },
                {
                  "name": "MDVSA-2011:090",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2011:090"
                },
                {
                  "name": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10705",
                  "refsource": "CONFIRM",
                  "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10705"
                },
                {
                  "name": "DSA-2233",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2011/dsa-2233"
                },
                {
                  "name": "USN-1131-1",
                  "refsource": "UBUNTU",
                  "url": "http://www.ubuntu.com/usn/usn-1131-1"
                },
                {
                  "name": "postfix-cyrus-sasl-code-exec(67359)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67359"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2011-1720",
        "datePublished": "2011-05-13T17:00:00.000Z",
        "dateReserved": "2011-04-18T00:00:00.000Z",
        "dateUpdated": "2024-08-06T22:37:25.642Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2011-0411 (GCVE-0-2011-0411)

    Vulnerability from cvelistv5 – Published: 2011-03-16 22:00 – Updated: 2024-08-06 21:51
    VLAI
    Summary
    The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.oracle.com/technetwork/topics/security… x_refsource_CONFIRM
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    http://www.postfix.org/CVE-2011-0411.html x_refsource_CONFIRM
    http://secunia.com/advisories/43646 third-party-advisoryx_refsource_SECUNIA
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    http://www.osvdb.org/71021 vdb-entryx_refsource_OSVDB
    http://www.vupen.com/english/advisories/2011/0752 vdb-entryx_refsource_VUPEN
    http://www.vupen.com/english/advisories/2011/0891 vdb-entryx_refsource_VUPEN
    http://security.gentoo.org/glsa/glsa-201206-33.xml vendor-advisoryx_refsource_GENTOO
    http://lists.fedoraproject.org/pipermail/package-… vendor-advisoryx_refsource_FEDORA
    http://secunia.com/advisories/43874 third-party-advisoryx_refsource_SECUNIA
    http://lists.fedoraproject.org/pipermail/package-… vendor-advisoryx_refsource_FEDORA
    http://www.kb.cert.org/vuls/id/MORO-8ELH6Z x_refsource_CONFIRM
    http://lists.apple.com/archives/Security-announce… vendor-advisoryx_refsource_APPLE
    http://www.vupen.com/english/advisories/2011/0611 vdb-entryx_refsource_VUPEN
    http://www.securityfocus.com/bid/46767 vdb-entryx_refsource_BID
    http://www.redhat.com/support/errata/RHSA-2011-04… vendor-advisoryx_refsource_REDHAT
    http://www.kb.cert.org/vuls/id/555316 third-party-advisoryx_refsource_CERT-VN
    http://securitytracker.com/id?1025179 vdb-entryx_refsource_SECTRACK
    http://www.redhat.com/support/errata/RHSA-2011-04… vendor-advisoryx_refsource_REDHAT
    http://support.apple.com/kb/HT5002 x_refsource_CONFIRM
    http://kb.juniper.net/InfoCenter/index?page=conte… x_refsource_CONFIRM
    http://www.debian.org/security/2011/dsa-2233 vendor-advisoryx_refsource_DEBIAN
    http://www.openwall.com/lists/oss-security/2021/08/10/2 mailing-listx_refsource_MLIST
    Date Public
    2011-03-03 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T21:51:08.944Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html"
              },
              {
                "name": "multiple-starttls-command-execution(65932)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/65932"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.postfix.org/CVE-2011-0411.html"
              },
              {
                "name": "43646",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/43646"
              },
              {
                "name": "SUSE-SR:2011:009",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html"
              },
              {
                "name": "71021",
                "tags": [
                  "vdb-entry",
                  "x_refsource_OSVDB",
                  "x_transferred"
                ],
                "url": "http://www.osvdb.org/71021"
              },
              {
                "name": "ADV-2011-0752",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0752"
              },
              {
                "name": "ADV-2011-0891",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0891"
              },
              {
                "name": "GLSA-201206-33",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-201206-33.xml"
              },
              {
                "name": "FEDORA-2011-3355",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056560.html"
              },
              {
                "name": "43874",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/43874"
              },
              {
                "name": "FEDORA-2011-3394",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056559.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/MORO-8ELH6Z"
              },
              {
                "name": "APPLE-SA-2011-10-12-3",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_APPLE",
                  "x_transferred"
                ],
                "url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html"
              },
              {
                "name": "ADV-2011-0611",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0611"
              },
              {
                "name": "46767",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/46767"
              },
              {
                "name": "RHSA-2011:0423",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2011-0423.html"
              },
              {
                "name": "VU#555316",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT-VN",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/555316"
              },
              {
                "name": "1025179",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://securitytracker.com/id?1025179"
              },
              {
                "name": "RHSA-2011:0422",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2011-0422.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://support.apple.com/kb/HT5002"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10705"
              },
              {
                "name": "DSA-2233",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2011/dsa-2233"
              },
              {
                "name": "[oss-security] 20210810 STARTTLS vulnerabilities",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2021/08/10/2"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2011-03-03T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a \"plaintext command injection\" attack."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-08-10T11:07:06.000Z",
            "orgId": "37e5125f-f79b-445b-8fad-9564f167944b",
            "shortName": "certcc"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html"
            },
            {
              "name": "multiple-starttls-command-execution(65932)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/65932"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.postfix.org/CVE-2011-0411.html"
            },
            {
              "name": "43646",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/43646"
            },
            {
              "name": "SUSE-SR:2011:009",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html"
            },
            {
              "name": "71021",
              "tags": [
                "vdb-entry",
                "x_refsource_OSVDB"
              ],
              "url": "http://www.osvdb.org/71021"
            },
            {
              "name": "ADV-2011-0752",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0752"
            },
            {
              "name": "ADV-2011-0891",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0891"
            },
            {
              "name": "GLSA-201206-33",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-201206-33.xml"
            },
            {
              "name": "FEDORA-2011-3355",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056560.html"
            },
            {
              "name": "43874",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/43874"
            },
            {
              "name": "FEDORA-2011-3394",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056559.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.kb.cert.org/vuls/id/MORO-8ELH6Z"
            },
            {
              "name": "APPLE-SA-2011-10-12-3",
              "tags": [
                "vendor-advisory",
                "x_refsource_APPLE"
              ],
              "url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html"
            },
            {
              "name": "ADV-2011-0611",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0611"
            },
            {
              "name": "46767",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/46767"
            },
            {
              "name": "RHSA-2011:0423",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2011-0423.html"
            },
            {
              "name": "VU#555316",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT-VN"
              ],
              "url": "http://www.kb.cert.org/vuls/id/555316"
            },
            {
              "name": "1025179",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://securitytracker.com/id?1025179"
            },
            {
              "name": "RHSA-2011:0422",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2011-0422.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://support.apple.com/kb/HT5002"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10705"
            },
            {
              "name": "DSA-2233",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2011/dsa-2233"
            },
            {
              "name": "[oss-security] 20210810 STARTTLS vulnerabilities",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2021/08/10/2"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cert@cert.org",
              "ID": "CVE-2011-0411",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a \"plaintext command injection\" attack."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html"
                },
                {
                  "name": "multiple-starttls-command-execution(65932)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/65932"
                },
                {
                  "name": "http://www.postfix.org/CVE-2011-0411.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.postfix.org/CVE-2011-0411.html"
                },
                {
                  "name": "43646",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/43646"
                },
                {
                  "name": "SUSE-SR:2011:009",
                  "refsource": "SUSE",
                  "url": "http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html"
                },
                {
                  "name": "71021",
                  "refsource": "OSVDB",
                  "url": "http://www.osvdb.org/71021"
                },
                {
                  "name": "ADV-2011-0752",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2011/0752"
                },
                {
                  "name": "ADV-2011-0891",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2011/0891"
                },
                {
                  "name": "GLSA-201206-33",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-201206-33.xml"
                },
                {
                  "name": "FEDORA-2011-3355",
                  "refsource": "FEDORA",
                  "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056560.html"
                },
                {
                  "name": "43874",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/43874"
                },
                {
                  "name": "FEDORA-2011-3394",
                  "refsource": "FEDORA",
                  "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056559.html"
                },
                {
                  "name": "http://www.kb.cert.org/vuls/id/MORO-8ELH6Z",
                  "refsource": "CONFIRM",
                  "url": "http://www.kb.cert.org/vuls/id/MORO-8ELH6Z"
                },
                {
                  "name": "APPLE-SA-2011-10-12-3",
                  "refsource": "APPLE",
                  "url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html"
                },
                {
                  "name": "ADV-2011-0611",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2011/0611"
                },
                {
                  "name": "46767",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/46767"
                },
                {
                  "name": "RHSA-2011:0423",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2011-0423.html"
                },
                {
                  "name": "VU#555316",
                  "refsource": "CERT-VN",
                  "url": "http://www.kb.cert.org/vuls/id/555316"
                },
                {
                  "name": "1025179",
                  "refsource": "SECTRACK",
                  "url": "http://securitytracker.com/id?1025179"
                },
                {
                  "name": "RHSA-2011:0422",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2011-0422.html"
                },
                {
                  "name": "http://support.apple.com/kb/HT5002",
                  "refsource": "CONFIRM",
                  "url": "http://support.apple.com/kb/HT5002"
                },
                {
                  "name": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10705",
                  "refsource": "CONFIRM",
                  "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10705"
                },
                {
                  "name": "DSA-2233",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2011/dsa-2233"
                },
                {
                  "name": "[oss-security] 20210810 STARTTLS vulnerabilities",
                  "refsource": "MLIST",
                  "url": "http://www.openwall.com/lists/oss-security/2021/08/10/2"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
        "assignerShortName": "certcc",
        "cveId": "CVE-2011-0411",
        "datePublished": "2011-03-16T22:00:00.000Z",
        "dateReserved": "2011-01-11T00:00:00.000Z",
        "dateUpdated": "2024-08-06T21:51:08.944Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }