Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.113214
Category:General
Title:Dovecot <= 2.2.33 DoS and Information Disclosure Vulnerability
Summary:Dovecot is prone to a vulnerability that may lead to Denial of Service and Information Disclosure.
Description:Summary:
Dovecot is prone to a vulnerability that may lead to Denial of Service and Information Disclosure.

Vulnerability Insight:
A specially crafted email delivered over SMTP and passed on to Dovecot can trigger an out of bounds read
resulting in potential sensitive information disclosure and denial of service.

In order to trigger this vulnerability, an attacker needs to send a specially crafted amail message to the server.

Affected Software/OS:
Dovecot version 2.0.0 through 2.2.33.

Solution:
Update to version 2.2.34.

CVSS Score:
5.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-14461
BugTraq ID: 103201
http://www.securityfocus.com/bid/103201
Debian Security Information: DSA-4130 (Google Search)
https://www.debian.org/security/2018/dsa-4130
https://talosintelligence.com/vulnerability_reports/TALOS-2017-0510
https://lists.debian.org/debian-lts-announce/2018/03/msg00036.html
https://www.dovecot.org/list/dovecot-news/2018-February/000370.html
https://usn.ubuntu.com/3587-1/
https://usn.ubuntu.com/3587-2/
CopyrightCopyright (C) 2018 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.