USN-3587-1
Dashboard / Vulnerabilities / USN-3587-1
USN-3587-1
Summary: dovecot vulnerabilities
Details: It was discovered that Dovecot incorrectly handled parsing certain email addresses. A remote attacker could use this issue to cause Dovecot to crash, resulting in a denial of service, or possibly obtain sensitive information. (CVE-2017-14461) It was discovered that Dovecot incorrectly handled TLS SNI config lookups. A remote attacker could possibly use this issue to cause Dovecot to crash, resulting in a denial of service. (CVE-2017-15130)
References: https://ubuntu.com/security/notices/USN-3587-1, https://ubuntu.com/security/CVE-2017-14461, https://ubuntu.com/security/CVE-2017-15130
Affected packages
Package
Name: dovecot
Purl: pkg:deb/ubuntu/dovecot@1:2.2.9-1ubuntu2.4?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
