|
|
Log in / Subscribe / Register

dovecot: denial of service

Package(s):dovecot CVE #(s):CVE-2015-3420
Created:April 29, 2015 Updated:May 20, 2015
Description: From the Arch Linux advisory:

Dovecot <= 2.2.14 does not correctly handle SSL/TLS handshake failure in the login process, asking OpenSSL to flush a connection that has already been aborted. This results in a crash with some versions of OpenSSL (most likely >= 1.0.2).

Alerts:
Arch Linux ASA-201504-31 dovecot 2015-04-29
Fedora FEDORA-2015-7159 dovecot 2015-05-19
Fedora FEDORA-2015-7089 dovecot 2015-05-19

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds