Out-of-bounds read in Dovecot - CVE-2017-14461

 

Out-of-bounds read in Dovecot - CVE-2017-14461

Published: March 2, 2018 / Updated: March 22, 2018


Vulnerability identifier: #VU10838
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14461
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information or cause DoS condition on the target system.

The weakness exists due to improper parsing of crafted email messages. A remote attacker can send a specially crafted email message over SMTP, trick the victim into opening it, trigger an out-of-bounds read and gain access to potentially sensitive information or cause the service to crash.


Affected software

Dovecot
Arch Linux
Debian Linux
Ubuntu
Fedora
dovecot (Alpine package)
dovecot

How to mitigate CVE-2017-14461

Update to version 2.2.34.

dovecot (Alpine package) - update to 2.2.34-r0
dovecot - addressed in versions 2.2.34-1.fc26, 2.2.34-1.fc27, 2.2.35-1.fc26

External References

Related Security Bulletins