Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-15132

Опубликовано: 09 янв. 2018
Источник: redhat
CVSS3: 5.3

Описание

A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration where same login processes are reused and can cause the process to crash due to memory exhaustion.

Aborting the process of SASL authentication can lead to a memory leak when the same login processes are reused. An attacker could use this flaw to cause a denial of service due to memory exhaustion.

Меры по смягчению последствий

This issue can be mitigated on vulnerable systems by limiting the login process to a single request per process, which is also the default value.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dovecotNot affected
Red Hat Enterprise Linux 6dovecotAffected
Red Hat Enterprise Linux 7dovecotAffected
Red Hat Enterprise Linux 8dovecotNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1532768dovecot: Auth leaks memory if SASL authentication is aborted

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration where same login processes are reused and can cause the process to crash due to memory exhaustion.

CVSS3: 7.5
nvd
около 8 лет назад

A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration where same login processes are reused and can cause the process to crash due to memory exhaustion.

CVSS3: 7.5
debian
около 8 лет назад

A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SA ...

suse-cvrf
почти 8 лет назад

Security update for dovecot22

suse-cvrf
почти 8 лет назад

Security update for dovecot22

5.3 Medium

CVSS3