V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2017-15132
AST
Medium

A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client u…

CVSS
5.3
Medium
EPSS
0.03
p86
Published
2017-01-01
Updated
2017-01-01
Description

A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration where same login processes are reused and can cause the process to crash due to memory exhaustion.

Tags · CWE
Pre-auth
CWE-400
CWE-772
CAPEC-147
CAPEC-227
CAPEC-469
CAPEC-492
Affected products
Debian_linux
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Timeline
2017-01-01
Published
2017-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.028 · p86
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-227 · CWE-400
└ via CAPEC-469 · CWE-772
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
dovecotTracked
dovecotTracked
dovecotTracked
dovecotTracked
dovecotTracked
dovecotTracked
dovecot-develTracked
debian_linux*Tracked
dovecot*Tracked
ubuntu_linux*Tracked
Source databases
AST
DEB
CVE
RED
UBU
Related vulnerabilities