Oval Definition:oval:org.mitre.oval:def:23310
Revision Date:2014-05-26Version:13
Title:ELSA-2011:0859: cyrus-imapd security update (Moderate)
Description:The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2011-1926
ELSA-2011:0859-01
Platform(s):Oracle Linux 6
Product(s):cyrus-imapd
Definition Synopsis
  • Oracle Linux 6.x
  • AND rpm test
  • cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.2
  • OR cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.2
  • OR cyrus-imapd is earlier than 0:2.3.16-6.el6_1.2
  • BACK