← Back

CVE-2011-1575

nvd nist
Published: May 23, 2011Modified: Apr 29, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted FTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.

Affected (87)

Products: Pureftpd: Pure Ftpd
1 product
Pure Ftpd
Configuration A
87 vulnerable
Vulnerable SoftwareAffected Versions
Pureftpd
Up to 1.0.29
Version 0.90
Version 0.91
Version 0.92
Version 0.93
Version 0.94
Version 0.95-pre1
Version 0.95-pre2
Version 0.95-pre3
Version 0.95-pre4
Version 0.95.1
Version 0.95.2
Version 0.95
Version 0.96.1
Version 0.96
Version 0.96pre1
Version 0.97-final
Version 0.97.1
Version 0.97.2
Version 0.97.3
Version 0.97.4
Version 0.97.5
Version 0.97.6
Version 0.97.7
Version 0.97.7pre1
Version 0.97.7pre2
Version 0.97.7pre3
Version 0.97pre1
Version 0.97pre2
Version 0.97pre3
Version 0.97pre4
Version 0.97pre5
Version 0.98-final
Version 0.98.1
Version 0.98.2
Version 0.98.2a
Version 0.98.3
Version 0.98.4
Version 0.98.5
Version 0.98.6
Version 0.98.7
Version 0.98pre1
Version 0.98pre2
Version 0.99.1
Version 0.99.1a
Version 0.99.1b
Version 0.99.2
Version 0.99.2a
Version 0.99.3
Version 0.99.4
Version 0.99.9
Version 0.99
Version 0.99a
Version 0.99b
Version 0.99pre1
Version 0.99pre2
Version 1.0.0
Version 1.0.10
Version 1.0.11
Version 1.0.12
Version 1.0.13a
Version 1.0.14
Version 1.0.15
Version 1.0.16a
Version 1.0.16b
Version 1.0.16c
Version 1.0.17
Version 1.0.17a
Version 1.0.18
Version 1.0.19
Version 1.0.1
Version 1.0.20
Version 1.0.21
Version 1.0.22
Version 1.0.24
Version 1.0.25
Version 1.0.26
Version 1.0.27
Version 1.0.28
Version 1.0.2
Version 1.0.3
Version 1.0.4
Version 1.0.5
Version 1.0.6
Version 1.0.7
Version 1.0.8
Version 1.0.9

Related CWEs

References (28)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.