CVE-2017-15130: Medium severity Dovecot dovecot vulnerability
A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart.
Other sources
TLS SNI config lookups may lead to excessive memory usage, causing imap-login/pop3-login VSZ limit to be reached and the process restarted. This happens only if Dovecot config has localname { } or local { } configuration blocks and attacker uses randomly generated SNI servernames.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-15130?
CVE-2017-15130 is a denial of service vulnerability found in dovecot before version 2.2.34.
What is the severity of CVE-2017-15130?
The severity of CVE-2017-15130 is high, with a CVSS score of 5.9.
How does CVE-2017-15130 impact dovecot?
CVE-2017-15130 allows an attacker to generate random SNI server names and exploit TLS SNI configuration lookups, leading to excessive memory usage and process restart.
Which versions of dovecot are affected by CVE-2017-15130?
CVE-2017-15130 affects dovecot versions before 2.2.34.
How can I fix CVE-2017-15130?
To fix CVE-2017-15130, upgrade to dovecot version 2.2.34 or higher.