Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-2669

Опубликовано: 21 июн. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 3.7

Описание

Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending specially crafted %variable fields could result in excessive memory usage causing the process to crash (and restart), or excessive CPU usage causing all authentications to hang.

РелизСтатусПримечание
devel

released

2.2.27-2ubuntu2
esm-infra-legacy/trusty

not-affected

1:2.2.9-1ubuntu2.1
esm-infra/xenial

not-affected

precise

not-affected

trusty

not-affected

1:2.2.9-1ubuntu2.1
trusty/esm

not-affected

1:2.2.9-1ubuntu2.1
upstream

needed

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

not-affected

Показывать по

EPSS

Процентиль: 91%
0.06874
Низкий

5 Medium

CVSS2

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
redhat
почти 9 лет назад

Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending specially crafted %variable fields could result in excessive memory usage causing the process to crash (and restart), or excessive CPU usage causing all authentications to hang.

CVSS3: 3.7
nvd
больше 7 лет назад

Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending specially crafted %variable fields could result in excessive memory usage causing the process to crash (and restart), or excessive CPU usage causing all authentications to hang.

CVSS3: 3.7
debian
больше 7 лет назад

Dovecot before version 2.2.29 is vulnerable to a denial of service. Wh ...

suse-cvrf
больше 8 лет назад

Security update for dovecot22

suse-cvrf
больше 8 лет назад

Security update for dovecot22

EPSS

Процентиль: 91%
0.06874
Низкий

5 Medium

CVSS2

3.7 Low

CVSS3