Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-15130

Опубликовано: 28 фев. 2018
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart.

A denial of service flaw was found in dovecot. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dovecotNot affected
Red Hat Enterprise Linux 6dovecotAffected
Red Hat Enterprise Linux 7dovecotAffected
Red Hat Enterprise Linux 8dovecotNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1532356dovecot: TLS SNI config lookups are inefficient and can be used for DoS

EPSS

Процентиль: 85%
0.02378
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 8 лет назад

A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart.

CVSS3: 5.9
nvd
почти 8 лет назад

A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart.

CVSS3: 5.9
debian
почти 8 лет назад

A denial of service flaw was found in dovecot before 2.2.34. An attack ...

suse-cvrf
больше 7 лет назад

Security update for dovecot22

suse-cvrf
больше 7 лет назад

Security update for dovecot22

EPSS

Процентиль: 85%
0.02378
Низкий

3.7 Low

CVSS3