PT-2014-1283 · Dovecot+4 · Dovecot-Ee+5
Published
2014-02-18
·
Updated
2024-06-15
·
CVE-2014-3430
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Dovecot versions 1.1 through 2.2.12
Dovecot-ee versions 2.1.7.7 and earlier
Dovecot-ee versions 2.2.x through 2.2.12.12
Description
The issue is related to the improper closure of old connections, which can be exploited by a remote attacker to cause a denial of service. This is achieved by sending specially crafted packets during the SSL/TLS handshake when establishing an IMAP/POP3 connection, leading to resource consumption.
Recommendations
For Dovecot versions 1.1 through 2.2.12, update to version 2.2.13 or later to resolve the issue.
For Dovecot-ee versions 2.1.7.7 and earlier, update to version 2.1.7.7 or later to resolve the issue.
For Dovecot-ee versions 2.2.x through 2.2.12.12, update to version 2.2.12.12 or later to resolve the issue.
Fix
DoS
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Dovecot
Dovecot-Ee
Red Hat
Ubuntu