CVE-2015-3420: Medium severity dovecot vulnerability
A flaw was found in the way Dovecot handled SSL handshake failures. A remote attacker could use this flaw to crash the imap-login and pop3-login processes.
Note that only Dovecot installations accepting SSL/TLS connections that have SSLv3 disabled are vulnerable.
Additional details:
http://dovecot.org/pipermail/dovecot/2015-April/100618.html http://seclists.org/oss-sec/2015/q2/288
Upstream patch:
http://hg.dovecot.org/dovecot-2.2/rev/86f535375750
Other sources
The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3420?
CVE-2015-3420 is considered a medium severity vulnerability due to potential disruptions in Dovecot services.
How do I fix CVE-2015-3420?
To fix CVE-2015-3420, upgrade Dovecot to version 2.2.17 or later.
What systems are affected by CVE-2015-3420?
CVE-2015-3420 affects Dovecot installations that accept SSL/TLS connections and have SSLv3 disabled.
Can CVE-2015-3420 lead to a denial of service?
Yes, CVE-2015-3420 can lead to a denial of service by crashing the imap-login and pop3-login processes.
Is my version of Dovecot vulnerable to CVE-2015-3420?
If your Dovecot version is 2.2.16 or older, you are vulnerable to CVE-2015-3420.