![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.113214 |
Category: | General |
Title: | Dovecot <= 2.2.33 DoS and Information Disclosure Vulnerability |
Summary: | Dovecot is prone to a vulnerability that may lead to Denial of Service and Information Disclosure. |
Description: | Summary: Dovecot is prone to a vulnerability that may lead to Denial of Service and Information Disclosure. Vulnerability Insight: A specially crafted email delivered over SMTP and passed on to Dovecot can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vulnerability, an attacker needs to send a specially crafted amail message to the server. Affected Software/OS: Dovecot version 2.0.0 through 2.2.33. Solution: Update to version 2.2.34. CVSS Score: 5.5 CVSS Vector: AV:N/AC:L/Au:S/C:P/I:N/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2017-14461 BugTraq ID: 103201 http://www.securityfocus.com/bid/103201 Debian Security Information: DSA-4130 (Google Search) https://www.debian.org/security/2018/dsa-4130 https://talosintelligence.com/vulnerability_reports/TALOS-2017-0510 https://lists.debian.org/debian-lts-announce/2018/03/msg00036.html https://www.dovecot.org/list/dovecot-news/2018-February/000370.html https://usn.ubuntu.com/3587-1/ https://usn.ubuntu.com/3587-2/ |
Copyright | Copyright (C) 2018 Greenbone AG |
This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |