490
VMScore

CVE-2017-14461

Published: 02/03/2018 Updated: 19/04/2022
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 7.1 | Impact Score: 4.2 | Exploitability Score: 2.8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:P

Vulnerability Summary

A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vulnerability, an attacker needs to send a specially crafted email message to the server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dovecot dovecot 2.2.33.2

debian debian linux 8.0

debian debian linux 9.0

ubuntu ubuntu 14.04

ubuntu ubuntu 16.04

ubuntu ubuntu 17.10

Vendor Advisories

Several security issues were fixed in Dovecot ...
Several security issues were fixed in Dovecot ...
Several vulnerabilities have been discovered in the Dovecot email server The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2017-14461 Aleksandar Nikolic of Cisco Talos and flxflndy discovered that Dovecot does not properly parse invalid email addresses, which may cause a crash or leak memory content ...
Debian Bug report logs - #891820 dovecot: CVE-2017-15130: TLS SNI config lookups are inefficient and can be used for DoS Package: src:dovecot; Maintainer for src:dovecot is Dovecot Maintainers <dovecot@packagesdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 1 Mar 2018 07:33:05 UTC Seve ...
Debian Bug report logs - #888432 dovecot: CVE-2017-15132: auth client leaks memory if SASL authentication is aborted Package: src:dovecot; Maintainer for src:dovecot is Dovecot Maintainers <dovecot@packagesdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 25 Jan 2018 14:42:02 UTC Severity ...
Debian Bug report logs - #891819 dovecot: CVE-2017-14461: rfc822_parse_domain information leak vulnerability Package: src:dovecot; Maintainer for src:dovecot is Dovecot Maintainers <dovecot@packagesdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 1 Mar 2018 07:33:02 UTC Severity: grave ...
A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service In order to trigger this vulnerability, an attacker needs to send a specially crafted email message to the server ...
A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure of an email from another user or may cause an application crash In order to trigger this vulnerability, an imap-authenticated attacker needs to send a specially crafted email messag ...