CVE-2017-14461
Description
A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vulnerability, an attacker needs to send a specially crafted email message to the server.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
CVE-2017-14461 NameCVE-2017-14461 DescriptionA specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vulnerability, an attacker needs to send a specially crafted email message to the server. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec,…
CVE-2017-14461
| Name | CVE-2017-14461 |
| Description | A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vulnerability, an attacker needs to send a specially crafted email message to the server. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DLA-1333-1, DSA-4130-1 |
| Debian Bugs | 891819 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| dovecot (PTS) | bullseye | 1:2.3.13+dfsg1-2+deb11u1 | fixed |
| bullseye (security) | 1:2.3.13+dfsg1-2+deb11u4 | fixed | |
| bookworm | 1:2.3.19.1+dfsg1-2.1+deb12u5 | fixed | |
| bookworm (security) | 1:2.3.19.1+dfsg1-2.1+deb12u6 | fixed | |
| trixie | 1:2.4.1+dfsg1-6+deb13u5 | fixed | |
| trixie (security) | 1:2.4.1+dfsg1-6+deb13u6 | fixed | |
| forky, sid | 1:2.4.4+dfsg1-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| dovecot | source | wheezy | 1:2.1.7-7+deb7u2 | DLA-1333-1 | ||
| dovecot | source | jessie | 1:2.2.13-12~deb8u4 | DSA-4130-1 | ||
| dovecot | source | stretch | 1:2.2.27-3+deb9u2 | DSA-4130-1 | ||
| dovecot | source | (unstable) | 1:2.2.34-1 | 891819 |
Notes
https://www.dovecot.org/list/dovecot-news/2018-February/000370.html
https://github.com/dovecot/core/commit/30dc856f7b97b75b0e0d69f5003d5d99a13249b4
https://github.com/dovecot/core/commit/8d65e2345e1dbedb00b662ee0abd05be2e7e6b7e
https://github.com/dovecot/core/commit/b72d864b8c34cb21076214c0b28101baec530141
https://github.com/dovecot/core/commit/e9b86842441a668b30796bff7d60828614570a1b
https://github.com/dovecot/core/commit/f5cd17a27f0b666567747f8c921ebe1026970f11
https://github.com/dovecot/core/commit/18a7a161c8dae6f630770a3cbab7374a0c3dd732
https://github.com/dovecot/core/commit/0ed696987e5e5d44e971da2a10f6275b276ece34
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0510
Apply commands
https://www.dovecot.org/list/dovecot-news/2018-February/000370.htmlhttps://github.com/dovecot/core/commit/30dc856f7b97b75b0e0d69f5003d5d99a13249b4https://github.com/dovecot/core/commit/8d65e2345e1dbedb00b662ee0abd05be2e7e6b7ehttps://github.com/dovecot/core/commit/b72d864b8c34cb21076214c0b28101baec530141https://github.com/dovecot/core/commit/e9b86842441a668b30796bff7d60828614570a1bhttps://github.com/dovecot/core/commit/f5cd17a27f0b666567747f8c921ebe1026970f11https://github.com/dovecot/core/commit/18a7a161c8dae6f630770a3cbab7374a0c3dd732https://github.com/dovecot/core/commit/0ed696987e5e5d44e971da2a10f6275b276ece34https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0510
OS impact
SUSE Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| — | Affected | — |
Arch Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| — | Fixed | 2.3.0.1-1 |
Debian Fixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 1:2.2.34-1 |
| sid | Fixed | 1:2.2.34-1 |
| forky | Fixed | 1:2.2.34-1 |
| bullseye | Fixed | 1:2.2.34-1 |
| bookworm | Fixed | 1:2.2.34-1 |
References
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.