FS#44757 - [dovecot] CVE-2015-3420: DoS in dovecot <= 2.2.16
Attached to Project:
Arch Linux
Opened by Remi Gacogne (rgacogne) - Tuesday, 28 April 2015, 11:18 GMT
Last edited by Andreas Radke (AndyRTR) - Tuesday, 28 April 2015, 19:14 GMT
Opened by Remi Gacogne (rgacogne) - Tuesday, 28 April 2015, 11:18 GMT
Last edited by Andreas Radke (AndyRTR) - Tuesday, 28 April 2015, 19:14 GMT
|
Details
Hello,
A vulnerability [1] has been found in Dovecot, allowing a remote unauthenticated attacker to crash a Dovecot login process. To be vulnerable, Dovecot has to accept SSL/TLS connections while having disabled the use of SSLv3. It looks like the vulnerability also requires a recent (1.0.2+ ?) version of OpenSSL, but I can confirm that Arch is vulnerable. Timo Sirainen has stated [2] that he will not release a new version for this specific issue only, so I think we should backport the fix [3]. [1]: http://seclists.org/oss-sec/2015/q2/288 [2]: http://dovecot.org/pipermail/dovecot/2015-April/100655.html [3]: http://hg.dovecot.org/dovecot-2.2/rev/86f535375750 |
This task depends upon
Closed by Andreas Radke (AndyRTR)
Tuesday, 28 April 2015, 19:14 GMT
Reason for closing: Fixed
Additional comments about closing: patch applied to 2.2.16-2
Tuesday, 28 April 2015, 19:14 GMT
Reason for closing: Fixed
Additional comments about closing: patch applied to 2.2.16-2