Resource management error in Dovecot - CVE-2019-11499
Published: May 6, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect resource management error within the submission-login when processing incorrect authentication messages over TLS secure channel. A remote attacker can send an invalid authentication message and crash the service.
Affected software
Arch Linux
Opensuse
Fedora
dovecot (Alpine package)
dovecot (Ubuntu package)
dovecot
Dell PowerProtect Cyber Recovery
How to mitigate CVE-2019-11499
dovecot (Alpine package) - update to 2.3.6-r0
dovecot (Ubuntu package) - addressed in versions 1:2.3.2.1-1ubuntu3.4, 1:2.3.4.1-1ubuntu2.2
dovecot - addressed in versions 2.3.6-3.fc29, 2.3.6-3.fc30
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8
External References
Related Security Bulletins
- Multiple vulnerabilities in Dovecot
- Arch Linux update for dovecot
- Ubuntu update for Dovecot
- OpenSUSE Linux update for dovecot23
- OpenSUSE Linux update for dovecot23
- Resource management error in dovecot (Alpine package)
- Multiple vulnerabilities in Dell EMC Cyber Recovery
- Fedora 30 update for dovecot
- Fedora 29 update for dovecot