Back

HIGH

dovecot: Auth leaks memory if SASL authentication is aborted

Published Jan 25, 2018

Description

A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration where same login processes are reused and can cause the process to crash due to memory exhaustion.

Affected products

Remediation

Red Hat mitigation

This issue can be mitigated on vulnerable systems by limiting the login process to a single request per process, which is also the default value.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 25, 2018
Updated Sep 17, 2024
Reserved Oct 8, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 9, 2018