oval:org.mitre.oval:def:23310

Definition Id: oval:org.mitre.oval:def:23310
 
Oval ID: oval:org.mitre.oval:def:23310
Title: ELSA-2011:0859: cyrus-imapd security update (Moderate)
Description: The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
Family: unix Class: patch
Reference(s): ELSA-2011:0859-01
CVE-2011-1926
Version: 6
Platform(s): Oracle Linux 6
Product(s): cyrus-imapd
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:16594
 
Oval ID: oval:org.mitre.oval:def:16594
Title: Oracle Linux 6.x
Description: The operating system installed on the system is Oracle Linux 6.x
Family: unix Class: inventory
Reference(s): cpe:/o:oracle:linux:6
Version: 5
Platform(s): Oracle Linux 6
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:23310