CVE Vulnerabilities

CVE-2014-3430

Improper Authentication

Published: May 14, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.12 does not properly close old connections, which allows remote attackers to cause a denial of service (resource consumption) via an incomplete SSL/TLS handshake for an IMAP/POP3 connection.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
DovecotDovecot1.1 (including)1.1 (including)
DovecotDovecot1.1-rc2 (including)1.1-rc2 (including)
DovecotDovecot1.1.0 (including)1.1.0 (including)
DovecotDovecot1.1.1 (including)1.1.1 (including)
DovecotDovecot1.1.2 (including)1.1.2 (including)
DovecotDovecot1.1.3 (including)1.1.3 (including)
DovecotDovecot1.1.4 (including)1.1.4 (including)
DovecotDovecot1.1.5 (including)1.1.5 (including)
DovecotDovecot1.1.6 (including)1.1.6 (including)
DovecotDovecot1.2.0 (including)1.2.0 (including)
DovecotDovecot1.2.1 (including)1.2.1 (including)
DovecotDovecot1.2.2 (including)1.2.2 (including)
DovecotDovecot1.2.3 (including)1.2.3 (including)
DovecotDovecot1.2.4 (including)1.2.4 (including)
DovecotDovecot1.2.5 (including)1.2.5 (including)
DovecotDovecot1.2.6 (including)1.2.6 (including)
DovecotDovecot1.2.7 (including)1.2.7 (including)
DovecotDovecot1.2.8 (including)1.2.8 (including)
DovecotDovecot1.2.9 (including)1.2.9 (including)
DovecotDovecot1.2.10 (including)1.2.10 (including)
DovecotDovecot1.2.11 (including)1.2.11 (including)
DovecotDovecot1.2.12 (including)1.2.12 (including)
DovecotDovecot1.2.13 (including)1.2.13 (including)
DovecotDovecot1.2.14 (including)1.2.14 (including)
DovecotDovecot1.2.15 (including)1.2.15 (including)
DovecotDovecot2.0-beta1 (including)2.0-beta1 (including)
DovecotDovecot2.0.0 (including)2.0.0 (including)
DovecotDovecot2.0.1 (including)2.0.1 (including)
DovecotDovecot2.0.2 (including)2.0.2 (including)
DovecotDovecot2.0.3 (including)2.0.3 (including)
DovecotDovecot2.0.4 (including)2.0.4 (including)
DovecotDovecot2.0.5 (including)2.0.5 (including)
DovecotDovecot2.0.6 (including)2.0.6 (including)
DovecotDovecot2.0.7 (including)2.0.7 (including)
DovecotDovecot2.0.8 (including)2.0.8 (including)
DovecotDovecot2.0.9 (including)2.0.9 (including)
DovecotDovecot2.0.10 (including)2.0.10 (including)
DovecotDovecot2.0.11 (including)2.0.11 (including)
DovecotDovecot2.0.12 (including)2.0.12 (including)
DovecotDovecot2.0.13 (including)2.0.13 (including)
DovecotDovecot2.0.14 (including)2.0.14 (including)
DovecotDovecot2.0.15 (including)2.0.15 (including)
DovecotDovecot2.1-rc1 (including)2.1-rc1 (including)
DovecotDovecot2.1-rc2 (including)2.1-rc2 (including)
DovecotDovecot2.1-rc3 (including)2.1-rc3 (including)
DovecotDovecot2.1-rc5 (including)2.1-rc5 (including)
DovecotDovecot2.1-rc6 (including)2.1-rc6 (including)
DovecotDovecot2.1-rc7 (including)2.1-rc7 (including)
DovecotDovecot2.1.0 (including)2.1.0 (including)
DovecotDovecot2.1.1 (including)2.1.1 (including)
DovecotDovecot2.1.2 (including)2.1.2 (including)
DovecotDovecot2.1.3 (including)2.1.3 (including)
DovecotDovecot2.1.4 (including)2.1.4 (including)
DovecotDovecot2.1.5 (including)2.1.5 (including)
DovecotDovecot2.1.6 (including)2.1.6 (including)
DovecotDovecot2.1.7 (including)2.1.7 (including)
DovecotDovecot2.1.8 (including)2.1.8 (including)
DovecotDovecot2.1.10 (including)2.1.10 (including)
DovecotDovecot2.1.11 (including)2.1.11 (including)
DovecotDovecot2.1.12 (including)2.1.12 (including)
DovecotDovecot2.1.13 (including)2.1.13 (including)
DovecotDovecot2.1.14 (including)2.1.14 (including)
DovecotDovecot2.1.15 (including)2.1.15 (including)
DovecotDovecot2.2-rc1 (including)2.2-rc1 (including)
DovecotDovecot2.2-rc2 (including)2.2-rc2 (including)
DovecotDovecot2.2-rc3 (including)2.2-rc3 (including)
DovecotDovecot2.2-rc4 (including)2.2-rc4 (including)
DovecotDovecot2.2-rc5 (including)2.2-rc5 (including)
DovecotDovecot2.2-rc6 (including)2.2-rc6 (including)
DovecotDovecot2.2-rc7 (including)2.2-rc7 (including)
DovecotDovecot2.2.0 (including)2.2.0 (including)
DovecotDovecot2.2.1 (including)2.2.1 (including)
DovecotDovecot2.2.2 (including)2.2.2 (including)
DovecotDovecot2.2.3 (including)2.2.3 (including)
DovecotDovecot2.2.4 (including)2.2.4 (including)
DovecotDovecot2.2.5 (including)2.2.5 (including)
DovecotDovecot2.2.6 (including)2.2.6 (including)
DovecotDovecot2.2.7 (including)2.2.7 (including)
DovecotDovecot2.2.8 (including)2.2.8 (including)
DovecotDovecot2.2.9 (including)2.2.9 (including)
DovecotDovecot2.2.10 (including)2.2.10 (including)
DovecotDovecot2.2.13-rc1 (including)2.2.13-rc1 (including)
Red Hat Enterprise Linux 6RedHatdovecot-1:2.0.9-7.el6_5.1*
Red Hat Enterprise Linux 7RedHatdovecot-1:2.2.10-4.el7_0.1*
DovecotUbuntudevel*
DovecotUbuntuesm-infra-legacy/trusty*
DovecotUbuntulucid*
DovecotUbuntuprecise*
DovecotUbuntuquantal*
DovecotUbuntusaucy*
DovecotUbuntutrusty*
DovecotUbuntutrusty/esm*
DovecotUbuntuupstream*

Potential Mitigations

References