Resource management error in Dovecot - CVE-2019-11499

 

Resource management error in Dovecot - CVE-2019-11499

Published: May 6, 2019


Vulnerability identifier: #VU18400
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11499
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect resource management error within the submission-login when processing incorrect authentication messages over TLS secure channel. A remote attacker can send an invalid authentication message and crash the service.


Affected software

Dovecot
Arch Linux
Opensuse
Fedora
dovecot (Alpine package)
dovecot (Ubuntu package)
dovecot
Dell PowerProtect Cyber Recovery

How to mitigate CVE-2019-11499

Install updates from vendor's website.

Dovecot - update to 2.3.6
dovecot (Alpine package) - update to 2.3.6-r0
dovecot (Ubuntu package) - addressed in versions 1:2.3.2.1-1ubuntu3.4, 1:2.3.4.1-1ubuntu2.2
dovecot - addressed in versions 2.3.6-3.fc29, 2.3.6-3.fc30
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8

External References

Related Security Bulletins