The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.
CVSS Details
- CVSS 3.1 Base Score: 7.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2011-006 | Aug 28, 2015 | Mar 16, 2011 |
| Apple Osx Postfix | — | Apply OS X security update 2011-006 | Dec 16, 2011 | Mar 16, 2011 |
| Centos_linux | — | Upgrade postfixUpgrade postfix-pflogsumm | Dec 1, 2016 | Mar 16, 2011 |
| Debian | — | Upgrade postfix | Jul 30, 2024 | Mar 16, 2011 |
| Freebsd | — | Upgrade postfix-currentUpgrade postfixUpgrade postfix-current-baseUpgrade postfix-baseUpgrade inn | Dec 10, 2025 | Mar 19, 2011 |
| Gentoo Linux | — | Upgrade mail-mta/postfix. | Oct 30, 2017 | Mar 16, 2011 |
| Oracle_linux | — | Upgrade postfixUpgrade postfix-pflogsummUpgrade postfix-perl-scripts | Oct 16, 2024 | Mar 16, 2011 |
| Postfix | — | Upgrade to the latest version of Postfix | Jul 3, 2014 | Mar 16, 2011 |
| Suse | — | Upgrade pure-ftpd | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade postfix | Nov 8, 2024 | Mar 16, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub