CVE-2017-15132
Summary
| CVE | CVE-2017-15132 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-25 20:29:00 UTC |
| Updated | 2019-10-09 23:24:00 UTC |
| Description | A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration where same login processes are reused and can cause the process to crash due to memory exhaustion. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-4130-1 dovecot |
DEBIAN |
www.debian.org |
Third Party Advisory |
| USN-3556-1: Dovecot vulnerability | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| USN-3556-2: Dovecot vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| [Dovecot-news] v2.2.34 released |
MLIST |
www.dovecot.org |
Vendor Advisory |
| Bug 1532768 – CVE-2017-15132 dovecot: Auth leaks memory if SASL authentication is aborted |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| [SECURITY] [DLA 1333-1] dovecot security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| github.com/dovecot/core/commit/1a29ed2f96da1be22fa5a4d96c7583aa81b8b060.... |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500152 Alpine Linux Security Update for dovecot
- 503802 Alpine Linux Security Update for dovecot