CVE Vulnerabilities

CVE-2017-15130

Published: Mar 02, 2018 | Modified: Oct 03, 2019
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
3.7 LOW
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM

A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart.

Affected Software

Name Vendor Start Version End Version
Dovecot Dovecot * 2.2.34 (excluding)
Dovecot Ubuntu artful *
Dovecot Ubuntu devel *
Dovecot Ubuntu trusty *
Dovecot Ubuntu upstream *
Dovecot Ubuntu xenial *

References