CVE-2014-3556
published 2014-12-29CVE-2014-3556: The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly…
PriorityP339medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
7.83%
94.0th percentile
The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nginx | < nginx 1.6.1-1 (bookworm) | nginx 1.6.1-1 (bookworm) |
| f5 | nginx | >= 0 < 1.6.1-1 | 1.6.1-1 |
| f5 | nginx | >= 0 < 1.6.1-1 | 1.6.1-1 |
| f5 | nginx | >= 0 < 1.6.1-1 | 1.6.1-1 |
| f5 | nginx | >= 0 < 1.6.1-1 | 1.6.1-1 |
| f5 | nginx | >= 1.5.6 < 1.6.1 | 1.6.1 |
| f5 | nginx | >= 1.7.0 < 1.7.4 | 1.7.4 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8277-2g6w-24gq: The STARTTLS implementation in mail/ngx_mail_smtp_handler
ghsa_unreviewed·2022-05-13·CVSS 6.8
CVE-2014-3556 [MEDIUM] CWE-77 GHSA-8277-2g6w-24gq: The STARTTLS implementation in mail/ngx_mail_smtp_handler
The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
OSV
CVE-2014-3556: The STARTTLS implementation in mail/ngx_mail_smtp_handler
osv·2014-12-29·CVSS 6.8
CVE-2014-3556 [MEDIUM] CVE-2014-3556: The STARTTLS implementation in mail/ngx_mail_smtp_handler
The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
Red Hat
nginx: SMTP STARTTLS plaintext injection flaw
vendor_redhat·2014-08-05·CVSS 6.8
CVE-2014-3556 [MEDIUM] nginx: SMTP STARTTLS plaintext injection flaw
nginx: SMTP STARTTLS plaintext injection flaw
The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
Statement: This issue did not affect the versions of nginx as shipped with Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 and 7.
Package: nginx14-nginx (Red Hat Software Collections) - Not affected
Package: nginx16-nginx (Red Hat Software Collections) - Affected
Debian
CVE-2014-3556: nginx - The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in...
vendor_debian·2014·CVSS 6.8
CVE-2014-3556 [MEDIUM] CVE-2014-3556: nginx - The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in...
The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
Scope: local
bookworm: resolved (fixed in 1.6.1-1)
bullseye: resolved (fixed in 1.6.1-1)
forky: resolved (fixed in 1.6.1-1)
sid: resolved (fixed in 1.6.1-1)
trixie: resolved (fixed in 1.6.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3556 nginx: SMTP STARTTLS plaintext injection flaw
bugzilla·2014-08-05·CVSS 6.8
CVE-2014-3556 [MEDIUM] CVE-2014-3556 nginx: SMTP STARTTLS plaintext injection flaw
CVE-2014-3556 nginx: SMTP STARTTLS plaintext injection flaw
Upstream [1] reports:
...
A bug in nginx SMTP proxy was found, which allows an attacker in a
privileged network position to inject commands into SSL sessions started
with the STARTTLS command, potentially making it possible to steal
sensitive information sent by clients (CVE-2014-3556).
The problem affects nginx 1.5.6 - 1.7.3.
The problem is fixed in nginx 1.7.4, 1.6.1.
Patch for the problem can be found here:
http://nginx.org/download/patch.2014.starttls.txt
[1]: http://mailman.nginx.org/pipermail/nginx-announce/2014/000144.html
Discussion:
Created nginx tracking bugs for this issue:
Affects: epel-7 [bug 1126892]
---
Statement:
This issue did not affect the versions of nginx as shipped with Red Hat Software Collection
Bugzilla
CVE-2014-3556 nginx: SMTP STARTTLS plaintext injection flaw [epel-7]
bugzilla·2014-08-05·CVSS 6.8
CVE-2014-3556 [MEDIUM] CVE-2014-3556 nginx: SMTP STARTTLS plaintext injection flaw [epel-7]
CVE-2014-3556 nginx: SMTP STARTTLS plaintext injection flaw [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for nginx: see blocks bug list for full
http://mailman.nginx.org/pipermail/nginx-announce/2014/000144.htmlhttp://marc.info/?l=bugtraq&m=142103967620673&w=2http://nginx.org/download/patch.2014.starttls.txthttps://bugzilla.redhat.com/show_bug.cgi?id=1126891http://mailman.nginx.org/pipermail/nginx-announce/2014/000144.htmlhttp://marc.info/?l=bugtraq&m=142103967620673&w=2http://nginx.org/download/patch.2014.starttls.txthttps://bugzilla.redhat.com/show_bug.cgi?id=1126891
2014-12-29
Published