7.5

CVE-2017-15132

A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration where same login processes are reused and can cause the process to crash due to memory exhaustion.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dovecot ≫ Dovecot Version >= 2.0.0 <= 2.2.33
Dovecot ≫ Dovecot Version 2.3.0
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 17.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.12% 0.863
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

CWE-772 Missing Release of Resource after Effective Lifetime

The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

https://usn.ubuntu.com/3556-2/
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1532768
Patch
Third Party Advisory
Issue Tracking
https://github.com/dovecot/core/commit/1a29ed2f96da1be22fa5a4d96c7583aa81b8b060.patch
Patch
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/03/msg00036.html
Third Party Advisory
Mailing List
https://usn.ubuntu.com/3556-1/
Third Party Advisory
https://www.debian.org/security/2018/dsa-4130
Third Party Advisory
https://www.dovecot.org/list/dovecot-news/2018-February/000370.html
Vendor Advisory