Oval Definition:oval:org.mitre.oval:def:23665
Revision Date:2014-05-26Version:14
Title:ELSA-2011:0843: postfix security update (Moderate)
Description:The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2011-1720
ELSA-2011:0843-01
Platform(s):Oracle Linux 6
Product(s):postfix
Definition Synopsis
  • Oracle Linux 6.x
  • AND rpm test
  • postfix-perl-scripts is earlier than 2:2.6.6-2.2.el6_1
  • OR postfix is earlier than 2:2.6.6-2.2.el6_1
  • BACK