CVE-2014-3430: Medium severity Dovecot dovecot vulnerability
Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.12 does not properly close old connections, which allows remote attackers to cause a denial of service (resource consumption) via an incomplete SSL/TLS handshake for an IMAP/POP3 connection.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3430?
CVE-2014-3430 is rated as a high severity vulnerability due to its potential to cause a denial of service through resource consumption.
How do I fix CVE-2014-3430?
To fix CVE-2014-3430, upgrade Dovecot to version 2.2.13 or later or apply the relevant patches provided by your distribution.
What impact does CVE-2014-3430 have on my system?
The impact of CVE-2014-3430 allows remote attackers to consume system resources by triggering denial of service via incomplete SSL/TLS handshakes.
Which versions are affected by CVE-2014-3430?
CVE-2014-3430 affects Dovecot versions 1.1 through 2.2.12.12, including numerous prior versions.
Is there a workaround for CVE-2014-3430 until I can upgrade?
Currently, there are no known effective workarounds for CVE-2014-3430; upgrading is the recommended solution.