← Back

CVE-2011-1506

nvd nist
Published: Mar 22, 2011Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

The STARTTLS implementation in Kerio Connect 7.1.4 build 2985 and MailServer 6.x does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411. NOTE: some of these details are obtained from third party information.

Affected (57)

2 products
Connect
Kerio Mailserver
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.1.4
Configuration B
56 vulnerable
Vulnerable SoftwareAffected Versions
Kerio
Version 5.0
Version 5.1.1
Version 5.1
Version 5.6.3
Version 5.6.4
Version 5.6.5
Version 5.7.0
Version 5.7.10
Version 5.7.1
Version 5.7.2
Version 5.7.3
Version 5.7.4
Version 5.7.5
Version 5.7.6
Version 5.7.7
Version 5.7.8
Version 5.7.9
Version 6.0.0
Version 6.0.10
Version 6.0.1
Version 6.0.2
Version 6.0.3
Version 6.0.4
Version 6.0.5
Version 6.0.6
Version 6.0.7
Version 6.0.8
Version 6.0.9
Version 6.0
Version 6.1.1
Version 6.1.2
Version 6.1.3
Version 6.1.3_patch_1
Version 6.1.4
Version 6.2.0
Version 6.2.1
Version 6.2.2
Version 6.3.0
Version 6.3.1
Version 6.3.1_p1
Version 6.3.1_p2
Version 6.4.0
Version 6.4.1
Version 6.4.2
Version 6.5.0
Version 6.5.0 patch_1
Version 6.5.1
Version 6.5.2
Version 6.6.0
Version 6.6.0 patch_1
Version 6.6.1
Version 6.6.2
Version 6.7.0
Version 6.7.1
Version 6.7.2
Version 6.7.3

References (12)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.