2017-05-03
ALT-BU-2017-3092-1
Branch p8 update bulletin.
Closed vulnerabilities
Published: 2018-06-21
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2017-2669
Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending specially crafted %variable fields could result in excessive memory usage causing the process to crash (and restart), or excessive CPU usage causing all authentications to hang.
Severity: HIGH (7.5)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
- [oss-security] 20170411 CVE-2017-2669: Dovecot DoS when passdb dict was used for authentication
- [oss-security] 20170411 CVE-2017-2669: Dovecot DoS when passdb dict was used for authentication
- 97536
- 97536
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2669
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2669
- [dovecot-news] 20170410 v2.2.29 released
- [dovecot-news] 20170410 v2.2.29 released
- https://github.com/dovecot/core/commit/000030feb7a30f193197f1aab8a7b04a26b42735.patch
- https://github.com/dovecot/core/commit/000030feb7a30f193197f1aab8a7b04a26b42735.patch
- DSA-3828
- DSA-3828