CVE-2017-14461

A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vulnerability, an attacker needs to send a specially crafted email message to the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dovecot:dovecot:2.2.33.2:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:ubuntu:ubuntu:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:ubuntu:ubuntu:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:ubuntu:ubuntu:17.10:*:*:*:*:*:*:*

History

21 Nov 2024, 03:12

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/103201 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/103201 - Third Party Advisory, VDB Entry
References () https://lists.debian.org/debian-lts-announce/2018/03/msg00036.html - () https://lists.debian.org/debian-lts-announce/2018/03/msg00036.html -
References () https://talosintelligence.com/vulnerability_reports/TALOS-2017-0510 - Third Party Advisory () https://talosintelligence.com/vulnerability_reports/TALOS-2017-0510 - Third Party Advisory
References () https://usn.ubuntu.com/3587-1/ - Patch, Third Party Advisory () https://usn.ubuntu.com/3587-1/ - Patch, Third Party Advisory
References () https://usn.ubuntu.com/3587-2/ - () https://usn.ubuntu.com/3587-2/ -
References () https://www.debian.org/security/2018/dsa-4130 - Third Party Advisory () https://www.debian.org/security/2018/dsa-4130 - Third Party Advisory
References () https://www.dovecot.org/list/dovecot-news/2018-February/000370.html - Issue Tracking, Vendor Advisory () https://www.dovecot.org/list/dovecot-news/2018-February/000370.html - Issue Tracking, Vendor Advisory
CVSS v2 : 5.5
v3 : 7.1
v2 : 5.5
v3 : 5.9

Information

Published : 2018-03-02 15:29

Updated : 2024-11-21 03:12


NVD link : CVE-2017-14461

Mitre link : CVE-2017-14461

CVE.ORG link : CVE-2017-14461


JSON object : View

Products Affected

debian

  • debian_linux

ubuntu

  • ubuntu

dovecot

  • dovecot
CWE
CWE-125

Out-of-bounds Read

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor