PT-2018-3409 · Dovecot+3 · Dovecot+3
CVE-2017-15132
·
Publicado
2018-01-20
·
Atualizado
2025-01-30
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
dovecot versions 2.0 through 2.2.33
dovecot version 2.3.0
Description:
A flaw in the SASL authentication process can cause a memory leak in dovecot's auth client, which is used by login processes. This issue can have significant impact in high-performance configurations where the same login processes are reused, potentially leading to process crashes due to memory exhaustion. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations:
For dovecot versions 2.0 through 2.2.33, consider updating to a version that fixes the memory leak issue.
For dovecot version 2.3.0, consider updating to a version that fixes the memory leak issue.
As a temporary workaround, consider restricting the reuse of login processes to minimize the risk of memory exhaustion.
Correção
Resource Exhaustion
Missing Release of Resource after Effective Lifetime
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Ubuntu
Dovecot