5.1
CVSSv2

CVE-2011-1926

Published: 23/05/2011 Updated: 30/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

The STARTTLS implementation in Cyrus IMAP Server prior to 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle malicious users to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.

Vulnerable Product Search on Vulmon Subscribe to Product

cmu cyrus imap server 2.4.2

cmu cyrus imap server 2.4.1

cmu cyrus imap server 2.4.0

cmu cyrus imap server 2.3.3

cmu cyrus imap server 2.3.2

cmu cyrus imap server 2.3.1

cmu cyrus imap server 2.3.0

cmu cyrus imap server 2.1.16

cmu cyrus imap server 2.3.11

cmu cyrus imap server 2.0.17

cmu cyrus imap server

cmu cyrus imap server 2.4.5

cmu cyrus imap server 2.3.7

cmu cyrus imap server 2.3.6

cmu cyrus imap server 2.3.12

cmu cyrus imap server 2.2.12

cmu cyrus imap server 2.2.11

cmu cyrus imap server 2.3.16

cmu cyrus imap server 2.3.14

cmu cyrus imap server 2.2.13

cmu cyrus imap server 2.3.9

cmu cyrus imap server 2.3.8

cmu cyrus imap server 2.3.15

cmu cyrus imap server 2.3.13

cmu cyrus imap server 2.2.9

cmu cyrus imap server 2.2.8

cmu cyrus imap server 2.1.18

cmu cyrus imap server 2.2.13p1

cmu cyrus imap server 2.4.4

cmu cyrus imap server 2.4.3

cmu cyrus imap server 2.3.5

cmu cyrus imap server 2.3.4

cmu cyrus imap server 2.3.10

cmu cyrus imap server 2.2.10

cmu cyrus imap server 2.1.17

Vendor Advisories

Debian Bug report logs - #627081 STARTTLS plaintext command injection Package: cyrus-imapd-22; Maintainer for cyrus-imapd-22 is (unknown); Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Tue, 17 May 2011 15:03:05 UTC Severity: grave Tags: lenny, security, sid, squeeze Found in versions cyrus-imapd-22/ ...
It was discovered that the STARTTLS implementation of the Kolab Cyrus IMAP server does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted IMAP, LMTP, NNTP and POP3 sessions by sending a cleartext command that is processed after TLS is in place For the oldstable distribution (lenny), this ...