VulnerabilityModified
CVE-2017-15130
A denial of service flaw was found in dovecot before 2.2.34.
MEDIUM 5.9EPSS 2.55%
Does this matter?
Lower severity and a low EPSS score (2.55%). Track it; it rarely justifies an emergency change on its own.
Description
A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.55% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- dovecot/dovecot · debian/debian linux · canonical/ubuntu linux
- Source
- secalert@redhat.com
References
- http://seclists.org/oss-sec/2018/q1/205Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1532356Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00036.html
- https://usn.ubuntu.com/3587-1/Third Party Advisory
- https://usn.ubuntu.com/3587-2/
- https://www.debian.org/security/2018/dsa-4130Third Party Advisory
- https://www.dovecot.org/list/dovecot-news/2018-February/000370.htmlRelease Notes, Vendor Advisory
- http://seclists.org/oss-sec/2018/q1/205Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1532356Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00036.html
- https://usn.ubuntu.com/3587-1/Third Party Advisory
- https://usn.ubuntu.com/3587-2/
- https://www.debian.org/security/2018/dsa-4130Third Party Advisory
- https://www.dovecot.org/list/dovecot-news/2018-February/000370.htmlRelease Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.