A specially crafted email delivered over SMTP and passed on...
Vulnerability Description
A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vulnerability, an attacker needs to send a specially crafted email message to the server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-14461
Credits & Attribution
No credits recorded in the NVD database.
References
- https://usn.ubuntu.com/3587-1/
- https://lists.debian.org/debian-lts-announce/2018/03/msg00036.html
- https://www.debian.org/security/2018/dsa-4130
- https://usn.ubuntu.com/3587-2/
- http://www.securityfocus.com/bid/103201
- https://www.dovecot.org/list/dovecot-news/2018-February/000370.html
- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0510
Affected Vendor
The Dovecot Project
View all reports →