The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Apache | — | Apply OS X security update 2011-006Upgrade macOS to the latest version | Aug 28, 2015 | May 13, 2011 |
| Apple Osx Postfix | — | Apply OS X security update 2011-006 | Mar 23, 2012 | May 13, 2011 |
| Centos_linux | — | Upgrade postfixUpgrade postfix-pflogsumm | Dec 1, 2016 | May 13, 2011 |
| Debian | — | Upgrade postfix | Jul 30, 2024 | May 13, 2011 |
| Freebsd | — | Upgrade postfix-current-baseUpgrade postfixUpgrade postfix-baseUpgrade postfix-current | Dec 10, 2025 | May 9, 2011 |
| Gentoo Linux | — | Upgrade mail-mta/postfix. | Oct 30, 2017 | May 13, 2011 |
| Oracle_linux | — | Upgrade postfix-pflogsummUpgrade postfix-perl-scriptsUpgrade postfix | Oct 16, 2024 | May 13, 2011 |
| Postfix | — | Upgrade to the latest version of Postfix | Jul 3, 2014 | May 13, 2011 |
| Suse | — | Upgrade postfix-docUpgrade postfix-develUpgrade postfix-postgresqlUpgrade postfixUpgrade postfix-mysql | Feb 17, 2015 | May 13, 2011 |
| Ubuntu | — | Upgrade postfix | Nov 8, 2024 | May 13, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub