dovecot: denial of service
| Package(s): | dovecot | CVE #(s): | CVE-2015-3420 | ||||||||||||
| Created: | April 29, 2015 | Updated: | May 20, 2015 | ||||||||||||
| Description: | From the Arch Linux advisory:
Dovecot <= 2.2.14 does not correctly handle SSL/TLS handshake failure in the login process, asking OpenSSL to flush a connection that has already been aborted. This results in a crash with some versions of OpenSSL (most likely >= 1.0.2). | ||||||||||||||
| Alerts: |
| ||||||||||||||
