Back

HIGH

dovecot: Dovecot DoS when passdb dict was used for authentication

Published Jun 21, 2018

Description

Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending specially crafted %variable fields could result in excessive memory usage causing the process to crash (and restart), or excessive CPU usage causing all authentications to hang.

Affected products

Remediation

Red Hat statement

Versions of dovecot shipped in Red Hat Enterprise Linux 5, 6 and 7 are not affected by this vulnerability.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 21, 2018
Updated Aug 5, 2024
Reserved Dec 1, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 10, 2017