Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.704130
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 4130-1 (dovecot - security update)
Zusammenfassung:Several vulnerabilities have been discovered in the Dovecot email;server. The Common Vulnerabilities and Exposures project identifies the;following issues:;;CVE-2017-14461Aleksandar Nikolic of Cisco Talos and flxflndy;discovered that;Dovecot does not properly parse invalid email addresses, which may;cause a crash or leak memory contents to an attacker.;;CVE-2017-15130It was discovered that TLS SNI config lookups may lead to excessive;memory usage, causing imap-login/pop3-login VSZ limit to be reached;and the process restarted, resulting in a denial of service. Only;Dovecot configurations containing local_name { } or local { };;configuration blocks are affected.;;CVE-2017-15132;It was discovered that Dovecot contains a memory leak flaw in the;login process on aborted SASL authentication.
Beschreibung:Summary:
Several vulnerabilities have been discovered in the Dovecot email
server. The Common Vulnerabilities and Exposures project identifies the
following issues:

CVE-2017-14461Aleksandar Nikolic of Cisco Talos and flxflndy
discovered that
Dovecot does not properly parse invalid email addresses, which may
cause a crash or leak memory contents to an attacker.

CVE-2017-15130It was discovered that TLS SNI config lookups may lead to excessive
memory usage, causing imap-login/pop3-login VSZ limit to be reached
and the process restarted, resulting in a denial of service. Only
Dovecot configurations containing local_name { } or local { }

configuration blocks are affected.

CVE-2017-15132
It was discovered that Dovecot contains a memory leak flaw in the
login process on aborted SASL authentication.

Affected Software/OS:
dovecot on Debian Linux

Solution:
For the oldstable distribution (jessie), these problems have been fixed
in version 1:2.2.13-12~
deb8u4.

For the stable distribution (stretch), these problems have been fixed in
version 1:2.2.27-3+deb9u2.

We recommend that you upgrade your dovecot packages.

CVSS Score:
5.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-14461
Common Vulnerability Exposure (CVE) ID: CVE-2017-15130
Common Vulnerability Exposure (CVE) ID: CVE-2017-15132
CopyrightCopyright (C) 2018 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.