Memory leak in Dovecot - CVE-2017-15132
Published: February 1, 2018 / Updated: March 22, 2018
Vulnerability identifier: #VU10346
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-15132
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to improper memory handling when the software aborts a Simple Authentication and Security Layer (SASL) authentication process. A remote attacker can reuse log-in processes to trigger a memory leak, consume excessive amounts of memory resources and cause the service to crash.
The weakness exists due to improper memory handling when the software aborts a Simple Authentication and Security Layer (SASL) authentication process. A remote attacker can reuse log-in processes to trigger a memory leak, consume excessive amounts of memory resources and cause the service to crash.
Affected software
Dovecot
Arch Linux
Debian Linux
Ubuntu
Fedora
dovecot (Alpine package)
dovecot
Arch Linux
Debian Linux
Ubuntu
Fedora
dovecot (Alpine package)
dovecot
How to mitigate CVE-2017-15132
Install update from vendor's website.
dovecot (Alpine package) - update to 2.2.34-r0
dovecot - addressed in versions 2.2.34-1.fc26, 2.2.34-1.fc27, 2.2.35-1.fc26
dovecot - addressed in versions 2.2.34-1.fc26, 2.2.34-1.fc27, 2.2.35-1.fc26