CVE-2016-8652: Input Validation
Published Feb 16, 2017
·Updated
The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authentication without setting a username.
Affected Software
1 affected component
Dovecot dovecot<=2.2.27
Event History
Feb 16, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Feb 17, 2017
Data Sourced
via NVD·02:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-8652?
CVE-2016-8652 has been classified as a denial of service vulnerability, allowing remote attackers to crash the Dovecot service.
2
How do I fix CVE-2016-8652?
To fix CVE-2016-8652, upgrade Dovecot to version 2.2.27 or later.
3
What versions of Dovecot are affected by CVE-2016-8652?
CVE-2016-8652 affects all versions of Dovecot prior to 2.2.27.
4
Can CVE-2016-8652 be exploited remotely?
Yes, CVE-2016-8652 can be exploited remotely by attackers.
5
What impact does CVE-2016-8652 have on my system?
The impact of CVE-2016-8652 is a denial of service condition, causing the Dovecot service to crash.