PT-2014-1283 · Dovecot+4 · Dovecot-Ee+5

Published

2014-02-18

·

Updated

2024-06-15

·

CVE-2014-3430

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Dovecot versions 1.1 through 2.2.12 Dovecot-ee versions 2.1.7.7 and earlier Dovecot-ee versions 2.2.x through 2.2.12.12
Description The issue is related to the improper closure of old connections, which can be exploited by a remote attacker to cause a denial of service. This is achieved by sending specially crafted packets during the SSL/TLS handshake when establishing an IMAP/POP3 connection, leading to resource consumption.
Recommendations For Dovecot versions 1.1 through 2.2.12, update to version 2.2.13 or later to resolve the issue. For Dovecot-ee versions 2.1.7.7 and earlier, update to version 2.1.7.7 or later to resolve the issue. For Dovecot-ee versions 2.2.x through 2.2.12.12, update to version 2.2.12.12 or later to resolve the issue.

Fix

DoS

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1208
BDU:2015-00046
CESA-2014_0790
CVE-2014-3430
DLA-0004-1
DSA-2954-1
MGASA-2014-0223
OPENSUSE-SU-2024:10158-1
RHSA-2014:0790
RHSA-2014_0790
USN-2213-1

Affected Products

Alt Linux
Centos
Dovecot
Dovecot-Ee
Red Hat
Ubuntu