← Vulnerability feed

Vulnerability record · CVE-2011-1720 · published 13 May 2011

CVE-2011-1720: Postfix memory buffer overflow vulnerability

Postfix · Postfix

The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.

6.8 CVSS 2.0 Medium EPSS 21% · top 2.5% CWE-119 · Memory buffer overflow
6.8CVSS 2.0 base score
21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
36References
16 Jun 2026Last modified by NVD

Description

The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00002.html
http://secunia.com/advisories/44500 Vendor Advisory
http://security.gentoo.org/glsa/glsa-201206-33.xml
http://securityreason.com/securityalert/8247
http://www.debian.org/security/2011/dsa-2233
http://www.kb.cert.org/vuls/id/727230 US Government Resource
http://www.mail-archive.com/postfix-announce%40postfix.org/msg00007.html
http://www.mandriva.com/security/advisories?name=MDVSA-2011:090
http://www.osvdb.org/72259
http://www.postfix.org/CVE-2011-1720.html Vendor Advisory
http://www.postfix.org/announcements/postfix-2.8.3.html Vendor Advisory
http://www.securityfocus.com/archive/1/517917/100/0/threaded
http://www.securityfocus.com/bid/47778 Patch
http://www.securitytracker.com/id?1025521
http://www.ubuntu.com/usn/usn-1131-1
https://bugzilla.redhat.com/show_bug.cgi?id=699035
https://exchange.xforce.ibmcloud.com/vulnerabilities/67359
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00002.html
http://secunia.com/advisories/44500 Vendor Advisory
http://security.gentoo.org/glsa/glsa-201206-33.xml
http://securityreason.com/securityalert/8247
http://www.debian.org/security/2011/dsa-2233
http://www.kb.cert.org/vuls/id/727230 US Government Resource
http://www.mail-archive.com/postfix-announce%40postfix.org/msg00007.html
http://www.mandriva.com/security/advisories?name=MDVSA-2011:090
http://www.osvdb.org/72259
http://www.postfix.org/CVE-2011-1720.html Vendor Advisory
http://www.postfix.org/announcements/postfix-2.8.3.html Vendor Advisory
http://www.securityfocus.com/archive/1/517917/100/0/threaded
http://www.securityfocus.com/bid/47778 Patch
http://www.securitytracker.com/id?1025521
http://www.ubuntu.com/usn/usn-1131-1
https://bugzilla.redhat.com/show_bug.cgi?id=699035
https://exchange.xforce.ibmcloud.com/vulnerabilities/67359

Track CVE-2011-1720 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2017-10140Postfix vulnerabilityPostfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undo…EPSS 0.55%7.5CVE-2026-43964Postfix vulnerabilityPostfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code th…EPSS 0.88%6.9CVE-2009-2939Postfix link following vulnerabilityThe postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, …EPSS 0.50%6.9CVE-2008-4977Postfix link following vulnerabilitypostfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /t…EPSS 0.37%6.8CVE-2011-0411Postfix permissions and access controls vulnerabilityThe STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restric…EPSS 16%6.5CVE-2012-0811Postfix sql injection vulnerabilityMultiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL com…EPSS 1.7%6.2CVE-2008-2936Postfix permissions and access controls vulnerabilityPostfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, al…EPSS 0.99%5.3CVE-2023-51764Postfix insufficient verification of data authenticity vulnerabilityPostfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=c…EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2011-1720), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.