PT-2014-1283 · Dovecot+4 · Dovecot-Ee+5
Publicado
2014-02-18
·
Atualizado
2024-06-15
·
CVE-2014-3430
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Dovecot versions 1.1 through 2.2.12
Dovecot-ee versions 2.1.7.7 and earlier
Dovecot-ee versions 2.2.x through 2.2.12.12
Description
The issue is related to the improper closure of old connections, which can be exploited by a remote attacker to cause a denial of service. This is achieved by sending specially crafted packets during the SSL/TLS handshake when establishing an IMAP/POP3 connection, leading to resource consumption.
Recommendations
For Dovecot versions 1.1 through 2.2.12, update to version 2.2.13 or later to resolve the issue.
For Dovecot-ee versions 2.1.7.7 and earlier, update to version 2.1.7.7 or later to resolve the issue.
For Dovecot-ee versions 2.2.x through 2.2.12.12, update to version 2.2.12.12 or later to resolve the issue.
Correção
DoS
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Dovecot
Dovecot-Ee
Red Hat
Ubuntu