Back to search
CVE-2015-3420
Published: Sep 19, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20150428 Re: Re: CVE request: Dovecot remote DoS on TLS connections
mailing-list
x_refsource_MLIST
[dovecot] 20150424 [patch] TLS Handshake failures can crash imap-login
mailing-list
x_refsource_MLIST
[dovecot-news] 20150513 [Dovecot-news] v2.2.17 released
mailing-list
x_refsource_MLIST
FEDORA-2015-7159
vendor-advisory
x_refsource_FEDORA
FEDORA-2015-7156
vendor-advisory
x_refsource_FEDORA
https://bugzilla.redhat.com/show_bug.cgi?id=1216057
x_refsource_CONFIRM
FEDORA-2015-7089
vendor-advisory
x_refsource_FEDORA
[oss-security] 20150427 Re: CVE request: Dovecot remote DoS on TLS connections
mailing-list
x_refsource_MLIST
74335
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now