PT-2014-1283 · Dovecot+4 · Dovecot-Ee+5

Publicado

2014-02-18

·

Atualizado

2024-06-15

·

CVE-2014-3430

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Dovecot versions 1.1 through 2.2.12 Dovecot-ee versions 2.1.7.7 and earlier Dovecot-ee versions 2.2.x through 2.2.12.12
Description The issue is related to the improper closure of old connections, which can be exploited by a remote attacker to cause a denial of service. This is achieved by sending specially crafted packets during the SSL/TLS handshake when establishing an IMAP/POP3 connection, leading to resource consumption.
Recommendations For Dovecot versions 1.1 through 2.2.12, update to version 2.2.13 or later to resolve the issue. For Dovecot-ee versions 2.1.7.7 and earlier, update to version 2.1.7.7 or later to resolve the issue. For Dovecot-ee versions 2.2.x through 2.2.12.12, update to version 2.2.12.12 or later to resolve the issue.

Correção

DoS

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1208
BDU:2015-00046
CESA-2014_0790
CVE-2014-3430
DLA-0004-1
DSA-2954-1
MGASA-2014-0223
OPENSUSE-SU-2024:10158-1
RHSA-2014:0790
RHSA-2014_0790
USN-2213-1

Produtos afetados

Alt Linux
Centos
Dovecot
Dovecot-Ee
Red Hat
Ubuntu