Resource exhaustion in Dovecot - CVE-2017-15130
Published: March 6, 2018 / Updated: March 22, 2018
Vulnerability identifier: #VU11218
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-15130
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to excessive memory usage. A remote attacker can cause the service to crash.
Affected software
Dovecot
Arch Linux
Debian Linux
Ubuntu
Fedora
Opensuse
dovecot (Alpine package)
dovecot
Arch Linux
Debian Linux
Ubuntu
Fedora
Opensuse
dovecot (Alpine package)
dovecot
How to mitigate CVE-2017-15130
Update to versions 2.2.34 or 2.3.0.1.
dovecot (Alpine package) - update to 2.2.34-r0
dovecot - addressed in versions 2.2.34-1.fc26, 2.2.34-1.fc27, 2.2.35-1.fc26
dovecot - addressed in versions 2.2.34-1.fc26, 2.2.34-1.fc27, 2.2.35-1.fc26