Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-3420

Опубликовано: 19 сент. 2017
Источник: debian
EPSS Низкий

Описание

The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dovecotfixed1:2.2.13-12package
dovecotfixed1:2.2.13-12~deb8u1jessiepackage
dovecotnot-affectedwheezypackage
dovecotnot-affectedsqueezepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2015/04/26/3

  • Patch: http://web.archive.org/web/20150907231530/http://hg.dovecot.org/dovecot-2.2/rev/86f535375750

  • Segfault reproducible if using openssl/1.0.2a-1 from sid.

  • http://dovecot.org/pipermail/dovecot/2015-April/100579.html

  • It is openssl crashing but because dovecot ignores an erlier

  • returned error from dovecot, related to openssl bug:

  • https://rt.openssl.org/Ticket/Display.html?id=3818&user=guest&pass=guest

  • Possibly introduced due to http://web.archive.org/web/20150121182933/http://hg.dovecot.org:80/dovecot-2.2/rev/09d3c9c6f0ad

EPSS

Процентиль: 92%
0.09152
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 8 лет назад

The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures.

redhat
больше 10 лет назад

The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures.

CVSS3: 5.9
nvd
почти 8 лет назад

The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures.

CVSS3: 5.9
github
больше 3 лет назад

The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures.

EPSS

Процентиль: 92%
0.09152
Низкий