CVE Vulnerabilities

CVE-2014-3430

Improper Authentication

Published: May 14, 2014 | Modified: Dec 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu

Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.12 does not properly close old connections, which allows remote attackers to cause a denial of service (resource consumption) via an incomplete SSL/TLS handshake for an IMAP/POP3 connection.

Weakness

When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Dovecot Dovecot 1.1 1.1
Dovecot Dovecot 1.1 1.1
Dovecot Dovecot 1.1.0 1.1.0
Dovecot Dovecot 1.1.1 1.1.1
Dovecot Dovecot 1.1.2 1.1.2
Dovecot Dovecot 1.1.3 1.1.3
Dovecot Dovecot 1.1.4 1.1.4
Dovecot Dovecot 1.1.5 1.1.5
Dovecot Dovecot 1.1.6 1.1.6
Dovecot Dovecot 1.2.0 1.2.0
Dovecot Dovecot 1.2.1 1.2.1
Dovecot Dovecot 1.2.2 1.2.2
Dovecot Dovecot 1.2.3 1.2.3
Dovecot Dovecot 1.2.4 1.2.4
Dovecot Dovecot 1.2.5 1.2.5
Dovecot Dovecot 1.2.6 1.2.6
Dovecot Dovecot 1.2.7 1.2.7
Dovecot Dovecot 1.2.8 1.2.8
Dovecot Dovecot 1.2.9 1.2.9
Dovecot Dovecot 1.2.10 1.2.10
Dovecot Dovecot 1.2.11 1.2.11
Dovecot Dovecot 1.2.12 1.2.12
Dovecot Dovecot 1.2.13 1.2.13
Dovecot Dovecot 1.2.14 1.2.14
Dovecot Dovecot 1.2.15 1.2.15
Dovecot Dovecot 2.0 2.0
Dovecot Dovecot 2.0.0 2.0.0
Dovecot Dovecot 2.0.1 2.0.1
Dovecot Dovecot 2.0.2 2.0.2
Dovecot Dovecot 2.0.3 2.0.3
Dovecot Dovecot 2.0.4 2.0.4
Dovecot Dovecot 2.0.5 2.0.5
Dovecot Dovecot 2.0.6 2.0.6
Dovecot Dovecot 2.0.7 2.0.7
Dovecot Dovecot 2.0.8 2.0.8
Dovecot Dovecot 2.0.9 2.0.9
Dovecot Dovecot 2.0.10 2.0.10
Dovecot Dovecot 2.0.11 2.0.11
Dovecot Dovecot 2.0.12 2.0.12
Dovecot Dovecot 2.0.13 2.0.13
Dovecot Dovecot 2.0.14 2.0.14
Dovecot Dovecot 2.0.15 2.0.15
Dovecot Dovecot 2.1 2.1
Dovecot Dovecot 2.1 2.1
Dovecot Dovecot 2.1 2.1
Dovecot Dovecot 2.1 2.1
Dovecot Dovecot 2.1 2.1
Dovecot Dovecot 2.1 2.1
Dovecot Dovecot 2.1.0 2.1.0
Dovecot Dovecot 2.1.1 2.1.1
Dovecot Dovecot 2.1.2 2.1.2
Dovecot Dovecot 2.1.3 2.1.3
Dovecot Dovecot 2.1.4 2.1.4
Dovecot Dovecot 2.1.5 2.1.5
Dovecot Dovecot 2.1.6 2.1.6
Dovecot Dovecot 2.1.7 2.1.7
Dovecot Dovecot 2.1.8 2.1.8
Dovecot Dovecot 2.1.10 2.1.10
Dovecot Dovecot 2.1.11 2.1.11
Dovecot Dovecot 2.1.12 2.1.12
Dovecot Dovecot 2.1.13 2.1.13
Dovecot Dovecot 2.1.14 2.1.14
Dovecot Dovecot 2.1.15 2.1.15
Dovecot Dovecot 2.2 2.2
Dovecot Dovecot 2.2 2.2
Dovecot Dovecot 2.2 2.2
Dovecot Dovecot 2.2 2.2
Dovecot Dovecot 2.2 2.2
Dovecot Dovecot 2.2 2.2
Dovecot Dovecot 2.2 2.2
Dovecot Dovecot 2.2.0 2.2.0
Dovecot Dovecot 2.2.1 2.2.1
Dovecot Dovecot 2.2.2 2.2.2
Dovecot Dovecot 2.2.3 2.2.3
Dovecot Dovecot 2.2.4 2.2.4
Dovecot Dovecot 2.2.5 2.2.5
Dovecot Dovecot 2.2.6 2.2.6
Dovecot Dovecot 2.2.7 2.2.7
Dovecot Dovecot 2.2.8 2.2.8
Dovecot Dovecot 2.2.9 2.2.9
Dovecot Dovecot 2.2.10 2.2.10
Dovecot Dovecot 2.2.13 2.2.13
Red Hat Enterprise Linux 6 RedHat dovecot-1:2.0.9-7.el6_5.1 *
Red Hat Enterprise Linux 7 RedHat dovecot-1:2.2.10-4.el7_0.1 *
Dovecot Ubuntu devel *
Dovecot Ubuntu lucid *
Dovecot Ubuntu precise *
Dovecot Ubuntu quantal *
Dovecot Ubuntu saucy *
Dovecot Ubuntu trusty *
Dovecot Ubuntu trusty/esm *
Dovecot Ubuntu upstream *

Potential Mitigations

References