5.8

CVE-2011-1575

The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted FTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.

Data is provided by the National Vulnerability Database (NVD)
PureftpdPure-ftpd Version <= 1.0.29
PureftpdPure-ftpd Version0.90
PureftpdPure-ftpd Version0.91
PureftpdPure-ftpd Version0.92
PureftpdPure-ftpd Version0.93
PureftpdPure-ftpd Version0.94
PureftpdPure-ftpd Version0.95
PureftpdPure-ftpd Version0.95-pre1
PureftpdPure-ftpd Version0.95-pre2
PureftpdPure-ftpd Version0.95-pre3
PureftpdPure-ftpd Version0.95-pre4
PureftpdPure-ftpd Version0.95.1
PureftpdPure-ftpd Version0.95.2
PureftpdPure-ftpd Version0.96
PureftpdPure-ftpd Version0.96.1
PureftpdPure-ftpd Version0.96pre1
PureftpdPure-ftpd Version0.97-final
PureftpdPure-ftpd Version0.97.1
PureftpdPure-ftpd Version0.97.2
PureftpdPure-ftpd Version0.97.3
PureftpdPure-ftpd Version0.97.4
PureftpdPure-ftpd Version0.97.5
PureftpdPure-ftpd Version0.97.6
PureftpdPure-ftpd Version0.97.7
PureftpdPure-ftpd Version0.97.7pre1
PureftpdPure-ftpd Version0.97.7pre2
PureftpdPure-ftpd Version0.97.7pre3
PureftpdPure-ftpd Version0.97pre1
PureftpdPure-ftpd Version0.97pre2
PureftpdPure-ftpd Version0.97pre3
PureftpdPure-ftpd Version0.97pre4
PureftpdPure-ftpd Version0.97pre5
PureftpdPure-ftpd Version0.98-final
PureftpdPure-ftpd Version0.98.1
PureftpdPure-ftpd Version0.98.2
PureftpdPure-ftpd Version0.98.2a
PureftpdPure-ftpd Version0.98.3
PureftpdPure-ftpd Version0.98.4
PureftpdPure-ftpd Version0.98.5
PureftpdPure-ftpd Version0.98.6
PureftpdPure-ftpd Version0.98.7
PureftpdPure-ftpd Version0.98pre1
PureftpdPure-ftpd Version0.98pre2
PureftpdPure-ftpd Version0.99
PureftpdPure-ftpd Version0.99.1
PureftpdPure-ftpd Version0.99.1a
PureftpdPure-ftpd Version0.99.1b
PureftpdPure-ftpd Version0.99.2
PureftpdPure-ftpd Version0.99.2a
PureftpdPure-ftpd Version0.99.3
PureftpdPure-ftpd Version0.99.4
PureftpdPure-ftpd Version0.99.9
PureftpdPure-ftpd Version0.99a
PureftpdPure-ftpd Version0.99b
PureftpdPure-ftpd Version0.99pre1
PureftpdPure-ftpd Version0.99pre2
PureftpdPure-ftpd Version1.0.0
PureftpdPure-ftpd Version1.0.1
PureftpdPure-ftpd Version1.0.2
PureftpdPure-ftpd Version1.0.3
PureftpdPure-ftpd Version1.0.4
PureftpdPure-ftpd Version1.0.5
PureftpdPure-ftpd Version1.0.6
PureftpdPure-ftpd Version1.0.7
PureftpdPure-ftpd Version1.0.8
PureftpdPure-ftpd Version1.0.9
PureftpdPure-ftpd Version1.0.10
PureftpdPure-ftpd Version1.0.11
PureftpdPure-ftpd Version1.0.12
PureftpdPure-ftpd Version1.0.13a
PureftpdPure-ftpd Version1.0.14
PureftpdPure-ftpd Version1.0.15
PureftpdPure-ftpd Version1.0.16a
PureftpdPure-ftpd Version1.0.16b
PureftpdPure-ftpd Version1.0.16c
PureftpdPure-ftpd Version1.0.17
PureftpdPure-ftpd Version1.0.17a
PureftpdPure-ftpd Version1.0.18
PureftpdPure-ftpd Version1.0.19
PureftpdPure-ftpd Version1.0.20
PureftpdPure-ftpd Version1.0.21
PureftpdPure-ftpd Version1.0.22
PureftpdPure-ftpd Version1.0.24
PureftpdPure-ftpd Version1.0.25
PureftpdPure-ftpd Version1.0.26
PureftpdPure-ftpd Version1.0.27
PureftpdPure-ftpd Version1.0.28
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 22.18% 0.953
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N