CVE-2017-15132: High severity Dovecot dovecot vulnerability
A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. A abort of SASL authentication results in a memory leak in Dovecot auth client used by login processes. The leak has impact in high performance configuration where same login processes are reused and can cause the process to crash due to memory exhaustion.
Upstream patch:
https://github.com/dovecot/core/commit/1a29ed2f96da1be22fa5a4d96c7583aa81b8b060.patch
https://github.com/dovecot/core/commit/a9b135760aea6d1790d447d351c56b78889dac22.patch
Other sources
A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration where same login processes are reused and can cause the process to crash due to memory exhaustion.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/dovecotto a version that resolves this vulnerability.Fixed in 2.2.34 - Upgrade
Upgrade
redhat/dovecotto a version that resolves this vulnerability.Fixed in 2.3.1 - Upgrade
Upgrade
debian/dovecotto a version that resolves this vulnerability.Fixed in 1:2.3.13+dfsg1-2+deb11u1Fixed in 1:2.3.13+dfsg1-2+deb11u4Fixed in 1:2.3.19.1+dfsg1-2.1+deb12u6Fixed in 1:2.4.1+dfsg1-6+deb13u6Fixed in 1:2.4.4+dfsg1-1
Event History
Frequently Asked Questions
What is the vulnerability ID for the dovecot memory leak vulnerability?
The vulnerability ID for the dovecot memory leak vulnerability is CVE-2017-15132.
What is the severity of CVE-2017-15132?
The severity of CVE-2017-15132 is high with a severity value of 7.5.
Which versions of dovecot are affected by CVE-2017-15132?
The versions of dovecot affected by CVE-2017-15132 are 2.0 up to 2.2.33 and 2.3.0.
How does the vulnerability CVE-2017-15132 impact high performance configuration?
The CVE-2017-15132 vulnerability can cause a memory leak in dovecot's auth client used by login processes, which can result in a process crash in high performance configurations.
How can I fix the CVE-2017-15132 vulnerability?
To fix the CVE-2017-15132 vulnerability, it is recommended to update to the latest patched version of dovecot.