Vulnerability Bulletins

DSA-3828 dovecot - security update

   
Affected software Debian
 
It was discovered that the Dovecot email server is vulnerable to adenial of service attack. When the dict passdb and userdb are usedfor user authentication, the username sent by the IMAP/POP3 client issent through var_expand() to perform %variable expansion. Sendingspecially crafted %variable fields could result in excessive memoryusage causing the process to crash (and restart).

More info:

https://www.debian.org/security/2017/dsa-3828