Unknown
CVE-2011-1575
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted FTP sessions by sending a cleartext command that is processed after TLS is in place, related to a “plaintext command injection” attack, a similar issue to CVE-2011-0411.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- pure-ftpd,
- pure-ftpd 0.90,
- pure-ftpd 0.91,
- pure-ftpd 0.92,
- pure-ftpd 0.93,
- pure-ftpd 0.94,
- pure-ftpd 0.95,
- pure-ftpd 0.95-pre1,
- pure-ftpd 0.95-pre2,
- pure-ftpd 0.95-pre3,
- pure-ftpd 0.95-pre4,
- pure-ftpd 0.95.1,
- pure-ftpd 0.95.2,
- pure-ftpd 0.96,
- pure-ftpd 0.96.1,
- pure-ftpd 0.96pre1,
- pure-ftpd 0.97-final,
- pure-ftpd 0.97.1,
- pure-ftpd 0.97.2,
- pure-ftpd 0.97.3,
- pure-ftpd 0.97.4,
- pure-ftpd 0.97.5,
- pure-ftpd 0.97.6,
- pure-ftpd 0.97.7,
- pure-ftpd 0.97.7pre1,
- pure-ftpd 0.97.7pre2,
- pure-ftpd 0.97.7pre3,
- pure-ftpd 0.97pre1,
- pure-ftpd 0.97pre2,
- pure-ftpd 0.97pre3,
- pure-ftpd 0.97pre4,
- pure-ftpd 0.97pre5,
- pure-ftpd 0.98-final,
- pure-ftpd 0.98.1,
- pure-ftpd 0.98.2,
- pure-ftpd 0.98.2a,
- pure-ftpd 0.98.3,
- pure-ftpd 0.98.4,
- pure-ftpd 0.98.5,
- pure-ftpd 0.98.6,
- pure-ftpd 0.98.7,
- pure-ftpd 0.98pre1,
- pure-ftpd 0.98pre2,
- pure-ftpd 0.99,
- pure-ftpd 0.99.1,
- pure-ftpd 0.99.1a,
- pure-ftpd 0.99.1b,
- pure-ftpd 0.99.2,
- pure-ftpd 0.99.2a,
- pure-ftpd 0.99.3,
- pure-ftpd 0.99.4,
- pure-ftpd 0.99.9,
- pure-ftpd 0.99a,
- pure-ftpd 0.99b,
- pure-ftpd 0.99pre1,
- pure-ftpd 0.99pre2,
- pure-ftpd 1.0.0,
- pure-ftpd 1.0.1,
- pure-ftpd 1.0.10,
- pure-ftpd 1.0.11,
- pure-ftpd 1.0.12,
- pure-ftpd 1.0.13a,
- pure-ftpd 1.0.14,
- pure-ftpd 1.0.15,
- pure-ftpd 1.0.16a,
- pure-ftpd 1.0.16b,
- pure-ftpd 1.0.16c,
- pure-ftpd 1.0.17,
- pure-ftpd 1.0.17a,
- pure-ftpd 1.0.18,
- pure-ftpd 1.0.19,
- pure-ftpd 1.0.2,
- pure-ftpd 1.0.20,
- pure-ftpd 1.0.21,
- pure-ftpd 1.0.22,
- pure-ftpd 1.0.24,
- pure-ftpd 1.0.25,
- pure-ftpd 1.0.26,
- pure-ftpd 1.0.27,
- pure-ftpd 1.0.28,
- pure-ftpd 1.0.3,
- pure-ftpd 1.0.4,
- pure-ftpd 1.0.5,
- pure-ftpd 1.0.6,
- pure-ftpd 1.0.7,
- pure-ftpd 1.0.8,
- pure-ftpd 1.0.9
References
Advisory
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: