CVE-2017-15130
Summary
| CVE | CVE-2017-15130 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-02 15:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 17.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 17.10 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Dovecot | Dovecot | All | All | All | All |
| Application | Dovecot | Dovecot | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| USN-3587-1: Dovecot vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| Debian -- Security Information -- DSA-4130-1 dovecot | DEBIAN | www.debian.org | Third Party Advisory |
| USN-3587-2: Dovecot vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| [Dovecot-news] v2.2.34 released | MLIST | www.dovecot.org | Release Notes, Vendor Advisory |
| 1532356 – (CVE-2017-15130) CVE-2017-15130 dovecot: TLS SNI config lookups are inefficient and can be used for DoS | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| [SECURITY] [DLA 1333-1] dovecot security update | MLIST | lists.debian.org | |
| oss-sec: Dovecot Security Advisory: CVE-2017-15130 TLS SNI config lookups are inefficient and can be used for DoS | MLIST | seclists.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.