Name | CVE-2017-14461 |
Description | A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vulnerability, an attacker needs to send a specially crafted email message to the server. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-1333-1, DSA-4130-1 |
Debian Bugs | 891819 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
dovecot (PTS) | bullseye | 1:2.3.13+dfsg1-2+deb11u1 | fixed |
bullseye (security) | 1:2.3.13+dfsg1-2+deb11u2 | fixed | |
bookworm, bookworm (security) | 1:2.3.19.1+dfsg1-2.1+deb12u1 | fixed | |
sid, trixie | 1:2.3.21.1+dfsg1-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
dovecot | source | wheezy | 1:2.1.7-7+deb7u2 | DLA-1333-1 | ||
dovecot | source | jessie | 1:2.2.13-12~deb8u4 | DSA-4130-1 | ||
dovecot | source | stretch | 1:2.2.27-3+deb9u2 | DSA-4130-1 | ||
dovecot | source | (unstable) | 1:2.2.34-1 | 891819 |
https://www.dovecot.org/list/dovecot-news/2018-February/000370.html
https://github.com/dovecot/core/commit/30dc856f7b97b75b0e0d69f5003d5d99a13249b4
https://github.com/dovecot/core/commit/8d65e2345e1dbedb00b662ee0abd05be2e7e6b7e
https://github.com/dovecot/core/commit/b72d864b8c34cb21076214c0b28101baec530141
https://github.com/dovecot/core/commit/e9b86842441a668b30796bff7d60828614570a1b
https://github.com/dovecot/core/commit/f5cd17a27f0b666567747f8c921ebe1026970f11
https://github.com/dovecot/core/commit/18a7a161c8dae6f630770a3cbab7374a0c3dd732
https://github.com/dovecot/core/commit/0ed696987e5e5d44e971da2a10f6275b276ece34
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0510