Memory leak in Dovecot - CVE-2017-15132

 

Memory leak in Dovecot - CVE-2017-15132

Published: February 1, 2018 / Updated: March 22, 2018


Vulnerability identifier: #VU10346
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-15132
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to improper memory handling when the software aborts a Simple Authentication and Security Layer (SASL) authentication process. A remote attacker can reuse log-in processes to trigger a memory leak, consume excessive amounts of memory resources and cause the service to crash.

Affected software

Dovecot
Arch Linux
Debian Linux
Ubuntu
Fedora
dovecot (Alpine package)
dovecot

How to mitigate CVE-2017-15132

Install update from vendor's website.

dovecot (Alpine package) - update to 2.2.34-r0
dovecot - addressed in versions 2.2.34-1.fc26, 2.2.34-1.fc27, 2.2.35-1.fc26

External References

Related Security Bulletins