Total vulnerabilities in the database
The STARTTLS implementation in nnrpd in INN before 2.5.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
Software | From | Fixed in |
---|---|---|
isc / inn | 1.5.1 | 1.5.1.x |
isc / inn | 2.2 | 2.2.x |
isc / inn | 2.2.2 | 2.2.2.x |
isc / inn | 1.4unoff4 | 1.4unoff4.x |
isc / inn | 1.4sec | 1.4sec.x |
isc / inn | 1.7.2 | 1.7.2.x |
isc / inn | 2.0 | 2.0.x |
isc / inn | 2.4.0 | 2.4.0.x |
isc / inn | 1.7 | 1.7.x |
isc / inn | 1.4unoff3 | 1.4unoff3.x |
isc / inn | 2.1 | 2.1.x |
isc / inn | 1.4 | 1.4.x |
isc / inn | 2.2.1 | 2.2.1.x |
isc / inn | 1.4sec2 | 1.4sec2.x |
isc / inn | 2.2.3 | 2.2.3.x |
isc / inn | - | 2.5.2.x |
isc / inn | 1.5 | 1.5.x |