ALT-PU-2018-2038-1
Closed vulnerabilities
BDU:2020-00779
Уязвимость почтового сервера Dovecot, связанная с чтением за границами буфера памяти, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании
BDU:2020-00780
Уязвимость реализации протоколов TLS почтового сервера Dovecot, связанная с исчерпанием ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2017-14461
A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vulnerability, an attacker needs to send a specially crafted email message to the server.
- 103201
- 103201
- [debian-lts-announce] 20180331 [SECURITY] [DLA 1333-1] dovecot security update
- [debian-lts-announce] 20180331 [SECURITY] [DLA 1333-1] dovecot security update
- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0510
- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0510
- USN-3587-1
- USN-3587-1
- USN-3587-2
- USN-3587-2
- DSA-4130
- DSA-4130
- [dovecot-news] 20180228 v2.2.34 released
- [dovecot-news] 20180228 v2.2.34 released
Modified: 2024-11-21
CVE-2017-15130
A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart.
- [oss-security] 20180301 Dovecot Security Advisory: CVE-2017-15130 TLS SNI config lookups are inefficient and can be used for DoS
- [oss-security] 20180301 Dovecot Security Advisory: CVE-2017-15130 TLS SNI config lookups are inefficient and can be used for DoS
- https://bugzilla.redhat.com/show_bug.cgi?id=1532356
- https://bugzilla.redhat.com/show_bug.cgi?id=1532356
- [debian-lts-announce] 20180331 [SECURITY] [DLA 1333-1] dovecot security update
- [debian-lts-announce] 20180331 [SECURITY] [DLA 1333-1] dovecot security update
- USN-3587-1
- USN-3587-1
- USN-3587-2
- USN-3587-2
- DSA-4130
- DSA-4130
- [dovecot-news] 20180228 v2.2.34 released
- [dovecot-news] 20180228 v2.2.34 released