[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2014-0790 -- Oracle dovecot

ID: oval:org.secpod.oval:def:1500606Date: (C)2014-07-20   (M)2022-10-10
Class: PATCHFamily: unix




Updated dovecot packages that fix one security issue are now available for Red Hat Enterprise Linux 6 and 7. The Red Hat Security Response Team has rated this update as having Moderate security impact. A Common Vulnerability Scoring System base score, which gives a detailed severity rating, is available from the CVE link in the References section. Dovecot is an IMAP server, written with security primarily in mind, for Linux and other UNIX-like systems. It also contains a small POP3 server. It supports mail in both the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages. It was discovered that Dovecot did not properly discard connections trapped in the SSL/TLS handshake phase. A remote attacker could use this flaw to cause a denial of service on an IMAP/POP3 server by exhausting the pool of available connections and preventing further, legitimate connections to the IMAP/POP3 server to be made. All dovecot users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. After installing the updated packages, the dovecot service will be restarted automatically.

Platform:
Oracle Linux 6
Product:
dovecot
Reference:
ELSA-2014-0790
CVE-2014-3430
CVE    1
CVE-2014-3430
CPE    75
cpe:/a:dovecot:dovecot:2.2:rc1
cpe:/a:dovecot:dovecot:2.2:rc2
cpe:/a:dovecot:dovecot:2.1.0
cpe:/a:dovecot:dovecot:2.1.1
...

© SecPod Technologies