Debian Security Advisory
DLA-0004-1 dovecot -- LTS security update
- Date Reported:
- 11 Jun 2014
- Affected Packages:
- dovecot
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 747549.
In Mitre's CVE dictionary: CVE-2014-3430. - More information:
-
It was discovered that the Dovecot email server is vulnerable to a denial of service attack against imap/pop3-login processes due to incorrect handling of the closure of inactive SSL/TLS connections.
For Debian 6
Squeeze
, these issues have been fixed in dovecot version 1:1.2.15-7+deb6u1