Total vulnerabilities in the database
Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending specially crafted %variable fields could result in excessive memory usage causing the process to crash (and restart), or excessive CPU usage causing all authentications to hang.
Software | From | Fixed in |
---|---|---|
dovecot / dovecot | 2.2.26 | 2.2.28.x |
debian / debian_linux | 8.0 | 8.0.x |