← Vulnerability feed

Vulnerability record · CVE-2011-0411 · published 16 March 2011

CVE-2011-0411: Postfix permissions and access controls vulnerability

Postfix · Postfix

The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.

6.8 CVSS 2.0 Medium EPSS 16% · top 3.1% CWE-264 · Permissions and access controls
6.8CVSS 2.0 base score
16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
48References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056559.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056560.html
http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html
http://secunia.com/advisories/43646 Vendor Advisory
http://secunia.com/advisories/43874
http://security.gentoo.org/glsa/glsa-201206-33.xml
http://securitytracker.com/id?1025179
http://support.apple.com/kb/HT5002
http://www.debian.org/security/2011/dsa-2233
http://www.kb.cert.org/vuls/id/555316 US Government Resource
http://www.kb.cert.org/vuls/id/MORO-8ELH6Z US Government Resource
http://www.openwall.com/lists/oss-security/2021/08/10/2
http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html
http://www.osvdb.org/71021
http://www.postfix.org/CVE-2011-0411.html ExploitVendor Advisory
http://www.redhat.com/support/errata/RHSA-2011-0422.html
http://www.redhat.com/support/errata/RHSA-2011-0423.html
http://www.securityfocus.com/bid/46767
http://www.vupen.com/english/advisories/2011/0611 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0752
http://www.vupen.com/english/advisories/2011/0891
https://exchange.xforce.ibmcloud.com/vulnerabilities/65932
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056559.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056560.html
http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html
http://secunia.com/advisories/43646 Vendor Advisory
http://secunia.com/advisories/43874
http://security.gentoo.org/glsa/glsa-201206-33.xml
http://securitytracker.com/id?1025179
http://support.apple.com/kb/HT5002
http://www.debian.org/security/2011/dsa-2233
http://www.kb.cert.org/vuls/id/555316 US Government Resource
http://www.kb.cert.org/vuls/id/MORO-8ELH6Z US Government Resource
http://www.openwall.com/lists/oss-security/2021/08/10/2
http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html
http://www.osvdb.org/71021

Track CVE-2011-0411 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2017-10140Postfix vulnerabilityPostfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undo…EPSS 0.55%7.5CVE-2026-43964Postfix vulnerabilityPostfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code th…EPSS 0.88%6.9CVE-2009-2939Postfix link following vulnerabilityThe postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, …EPSS 0.50%6.9CVE-2008-4977Postfix link following vulnerabilitypostfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /t…EPSS 0.37%6.8CVE-2011-1720Postfix memory buffer overflow vulnerabilityThe SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication met…EPSS 21%6.5CVE-2012-0811Postfix sql injection vulnerabilityMultiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL com…EPSS 1.7%6.2CVE-2008-2936Postfix permissions and access controls vulnerabilityPostfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, al…EPSS 0.99%5.3CVE-2023-51764Postfix insufficient verification of data authenticity vulnerabilityPostfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=c…EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2011-0411), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.