CVE-2017-14461
Summary
| CVE | CVE-2017-14461 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-02 15:29:00 UTC |
| Updated | 2022-04-19 19:15:00 UTC |
| Description | A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vulnerability, an attacker needs to send a specially crafted email message to the server. |
Risk And Classification
Problem Types: CWE-200 | CWE-125
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Dovecot | Dovecot | 2.2.33.2 | All | All | All |
| Application | Dovecot | Dovecot | 2.2.33.2 | All | All | All |
| Operating System | Ubuntu | Ubuntu | 14.04 | All | All | All |
| Operating System | Ubuntu | Ubuntu | 16.04 | All | All | All |
| Operating System | Ubuntu | Ubuntu | 17.10 | All | All | All |
| Operating System | Ubuntu | Ubuntu | 14.04 | All | All | All |
| Operating System | Ubuntu | Ubuntu | 16.04 | All | All | All |
| Operating System | Ubuntu | Ubuntu | 17.10 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| USN-3587-1: Dovecot vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | Patch, Third Party Advisory |
| Debian -- Security Information -- DSA-4130-1 dovecot | DEBIAN | www.debian.org | Third Party Advisory |
| USN-3587-2: Dovecot vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| [Dovecot-news] v2.2.34 released | MLIST | www.dovecot.org | Issue Tracking, Vendor Advisory |
| TALOS-2017-0510 || Cisco Talos Intelligence Group - Comprehensive Threat Intelligence | MISC | talosintelligence.com | Third Party Advisory |
| Malformed Request | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| [SECURITY] [DLA 1333-1] dovecot security update | MLIST | lists.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.