RHSA-2014:0790-01 -- Redhat dovecotID: oval:org.secpod.oval:def:501327 | Date: (C)2014-07-04 (M)2023-07-28 |
Class: PATCH | Family: unix |
Dovecot is an IMAP server, written with security primarily in mind, for Linux and other UNIX-like systems. It also contains a small POP3 server. It supports mail in both the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages. It was discovered that Dovecot did not properly discard connections trapped in the SSL/TLS handshake phase. A remote attacker could use this flaw to cause a denial of service on an IMAP/POP3 server by exhausting the pool of available connections and preventing further, legitimate connections to the IMAP/POP3 server to be made. All dovecot users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. After installing the updated packages, the dovecot service will be restarted automatically.
Platform: |
Red Hat Enterprise Linux 7 |
Red Hat Enterprise Linux 6 |