Vulnerability Bulletins |
DSA-3828 dovecot - security update |
|
| Affected software | Debian |
|
It was discovered that the Dovecot email server is vulnerable to adenial of service attack. When the dict passdb and userdb are usedfor user authentication, the username sent by the IMAP/POP3 client issent through var_expand() to perform %variable expansion. Sendingspecially crafted %variable fields could result in excessive memoryusage causing the process to crash (and restart). More info: https://www.debian.org/security/2017/dsa-3828 |
|






