A flaw was found in dovecot 2.0 up to 2.2.33...
Vulnerability Description
A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration where same login processes are reused and can cause the process to crash due to memory exhaustion.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-15132
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/dovecot/core/commit/1a29ed2f96da1be22fa5a4d96c7583aa81b8b060.patch
- https://lists.debian.org/debian-lts-announce/2018/03/msg00036.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1532768
- https://www.debian.org/security/2018/dsa-4130
- https://usn.ubuntu.com/3556-1/
- https://usn.ubuntu.com/3556-2/
- https://www.dovecot.org/list/dovecot-news/2018-February/000370.html
Affected Vendor
The Dovecot Project
View all reports →