Paketname
dovecot
Datum
2014-05-16
Advisory ID
MDVSA-2014:099
Betroffene Versionen
MES5 i586 , MBS1 x86_64 , MES5 x86_64

Problembeschreibung

A vulnerability has been discovered and corrected in dovecot:

Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x
before 2.2.12.12 does not properly close old connections, which allows
remote attackers to cause a denial of service (resource consumption)
via an incomplete SSL/TLS handshake for an IMAP/POP3 connection
(CVE-2014-3430).

The updated packages have been patched to correct this issue.

Aktualisierte Pakete

MES5 i586

 f43c0fd89c04fa2c294782e24a8ec358  mes5/i586/dovecot-1.1.6-0.5mdvmes5.2.i586.rpm
 c55e94781c0da3eb04a7cb943395de32  mes5/i586/dovecot-devel-1.1.6-0.5mdvmes5.2.i586.rpm
 75308a760c2c78a1616786c1d09f384b  mes5/i586/dovecot-plugins-gssapi-1.1.6-0.5mdvmes5.2.i586.rpm
 b339731e00b84f82d47e2b2b649bf5c9  mes5/i586/dovecot-plugins-ldap-1.1.6-0.5mdvmes5.2.i586.rpm 
 614b17acd72c3566abcd3f1c910dee0a  mes5/SRPMS/dovecot-1.1.6-0.5mdvmes5.2.src.rpm

MBS1 x86_64

 45e48e799a602ec746754f51d83d773d  mbs1/x86_64/dovecot-1.2.17-5.1.mbs1.x86_64.rpm
 0dbdeaa62c6d4d51d13fa7c1934e645a  mbs1/x86_64/dovecot-devel-1.2.17-5.1.mbs1.x86_64.rpm
 f766f74ff769386991c9eecbc18f7735  mbs1/x86_64/dovecot-plugins-gssapi-1.2.17-5.1.mbs1.x86_64.rpm
 a81fb27f431c215a6770560a23928baa  mbs1/x86_64/dovecot-plugins-ldap-1.2.17-5.1.mbs1.x86_64.rpm
 7dfb27e36bbe23789ce887089fd7cffb  mbs1/x86_64/dovecot-plugins-managesieve-1.2.17-5.1.mbs1.x86_64.rpm
 ec112e4fad85e6fb44f45e21bd9ac71b  mbs1/x86_64/dovecot-plugins-mysql-1.2.17-5.1.mbs1.x86_64.rpm
 c8b5177c354eeaacf07a946178d2304e  mbs1/x86_64/dovecot-plugins-pgsql-1.2.17-5.1.mbs1.x86_64.rpm
 92ae9ff2deecdb20f8d95842fa6ffca6  mbs1/x86_64/dovecot-plugins-sieve-1.2.17-5.1.mbs1.x86_64.rpm
 7ac32e0bccd481724bad4504286a8321  mbs1/x86_64/dovecot-plugins-sqlite-1.2.17-5.1.mbs1.x86_64.rpm 
 cb4efdf2ea2a20af60e6dfe4f425543d  mbs1/SRPMS/dovecot-1.2.17-5.1.mbs1.src.rpm

MES5 x86_64

 c5042b751df4a9fc6485641a74430bfd  mes5/x86_64/dovecot-1.1.6-0.5mdvmes5.2.x86_64.rpm
 4ced64eccb24e35abe995171e5a27177  mes5/x86_64/dovecot-devel-1.1.6-0.5mdvmes5.2.x86_64.rpm
 7baa83fdb419faa13773e88258a41e58  mes5/x86_64/dovecot-plugins-gssapi-1.1.6-0.5mdvmes5.2.x86_64.rpm
 b40dbd719a513945f77b94e524e39a75  mes5/x86_64/dovecot-plugins-ldap-1.1.6-0.5mdvmes5.2.x86_64.rpm 
 614b17acd72c3566abcd3f1c910dee0a  mes5/SRPMS/dovecot-1.1.6-0.5mdvmes5.2.src.rpm

Referenzen