CVE-2017-14461

Description

A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vulnerability, an attacker needs to send a specially crafted email message to the server.

Risk Information

Base Score
7.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
EPSS Score
Exploitation Probability
1.746

Associated Vulnerability

VulnerabilityOS Platform
IMAP and POP3 email server (USN-3587-1) dovecot-core_2.2.9-1ubuntu2.4_i386.debLinux
IMAP and POP3 email server (USN-3587-1) dovecot-core_2.2.9-1ubuntu2.4_amd64.debLinux
IMAP and POP3 email server (USN-3587-1) dovecot-core_2.2.22-1ubuntu2.7_i386.debLinux
IMAP and POP3 email server (USN-3587-1) dovecot-core_2.2.22-1ubuntu2.7_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234