Loading HuntDB...

GHSA-2gf2-4wwm-4cm6

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.

Related CVEs

Key Information

GHSA ID
GHSA-2gf2-4wwm-4cm6
Published
May 13, 2022 1:07 AM
Last Modified
May 13, 2022 1:07 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 29, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.