Medium severity5.9NVD Advisory· Published Sep 19, 2017· Updated May 13, 2026
CVE-2015-3420
CVE-2015-3420
Description
The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures.
Affected products
4cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- lists.fedoraproject.org/pipermail/package-announce/2015-May/157030.htmlnvdThird Party Advisory
- lists.fedoraproject.org/pipermail/package-announce/2015-May/158236.htmlnvdThird Party Advisory
- lists.fedoraproject.org/pipermail/package-announce/2015-May/158261.htmlnvdThird Party Advisory
- www.openwall.com/lists/oss-security/2015/04/27/1nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2015/04/28/4nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/74335nvdThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- dovecot.org/pipermail/dovecot-news/2015-May/000292.htmlnvdVendor Advisory
- dovecot.org/pipermail/dovecot/2015-April/100618.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.