Lucene search

K
ubuntucveUbuntu.comUB:CVE-2017-15130
HistoryFeb 28, 2018 - 12:00 a.m.

CVE-2017-15130

2018-02-2800:00:00
ubuntu.com
ubuntu.com
9

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.007

Percentile

79.8%

A denial of service flaw was found in dovecot before 2.2.34. An attacker
able to generate random SNI server names could exploit TLS SNI
configuration lookups, leading to excessive memory usage and the process to
restart.

Notes

Author Note
mdeslaur affects 2.2.0 - 2.2.33, 2.3.0
OSVersionArchitecturePackageVersionFilename
ubuntu17.10noarchdovecot< 1:2.2.27-3ubuntu1.3UNKNOWN
ubuntu14.04noarchdovecot< 1:2.2.9-1ubuntu2.4UNKNOWN
ubuntu16.04noarchdovecot< 1:2.2.22-1ubuntu2.7UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.007

Percentile

79.8%