Is SMG vulnerable to CVE-2014-3556
search cancel

Is SMG vulnerable to CVE-2014-3556

book

Article ID: 266906

calendar_today

Updated On:

Products

Messaging Gateway Messaging Gateway for Service Providers

Issue/Introduction

The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411

 

Cause

CVE-2011-0411 has been addressed in Symantec Messaging Gateway as of version 10.0. For more details refer to the databases shown below:

National Vulnerability Database    
CVE Database

Resolution

The SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 

Messaging Gateway does not use nginx. This CVE is not applicable.