Oval Definition:oval:org.mitre.oval:def:25127
Revision Date:2014-08-18Version:11
Title:RHSA-2014:0790: dovecot security update (Moderate)
Description:Dovecot is an IMAP server, written with security primarily in mind, forLinux and other UNIX-like systems. It also contains a small POP3 server.It supports mail in both the maildir or mbox format. The SQL drivers andauthentication plug-ins are provided as subpackages.It was discovered that Dovecot did not properly discard connections trappedin the SSL/TLS handshake phase. A remote attacker could use this flaw tocause a denial of service on an IMAP/POP3 server by exhausting the pool ofavailable connections and preventing further, legitimate connections to theIMAP/POP3 server to be made. (CVE-2014-3430)All dovecot users are advised to upgrade to these updated packages, whichcontain a backported patch to correct this issue. After installing theupdated packages, the dovecot service will be restarted automatically.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2014:0790
CVE-2014-3430
RHSA-2014:0790-00
Platform(s):CentOS Linux 6
CentOS Linux 7
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Product(s):dovecot
Definition Synopsis
  • Operation system section
  • Redhat 6 or Centos 6 release
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • OR The operating system installed on the system is CentOS Linux 6.x
  • AND Packages section
  • dovecot-pigeonhole is earlier than 1:2.0.9-7.el6_5.1
  • OR dovecot-mysql is earlier than 1:2.0.9-7.el6_5.1
  • OR dovecot is earlier than 1:2.0.9-7.el6_5.1
  • OR dovecot-devel is earlier than 1:2.0.9-7.el6_5.1
  • OR dovecot-pgsql is earlier than 1:2.0.9-7.el6_5.1
  • Operation system section
  • Redhat 7 or Centos 7 release
  • The operating system installed on the system is Red Hat Enterprise Linux 7
  • OR The operating system installed on the system is CentOS Linux 7.x
  • AND Packages section
  • dovecot-pigeonhole is earlier than 1:2.2.10-4.el7_0.1
  • OR dovecot-mysql is earlier than 1:2.2.10-4.el7_0.1
  • OR dovecot is earlier than 1:2.2.10-4.el7_0.1
  • OR dovecot-pgsql is earlier than 1:2.2.10-4.el7_0.1
  • BACK