Medium severity5.9NVD Advisory· Published Mar 2, 2018· Updated Jun 17, 2026
CVE-2017-14461
CVE-2017-14461
Description
A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vulnerability, an attacker needs to send a specially crafted email message to the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13cpe:2.3:a:dovecot:dovecot:2.2.33.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:dovecot:dovecot:2.2.33.2:*:*:*:*:*:*:*
- (no CPE)
- osv-coords5 versionspkg:rpm/opensuse/dovecot23&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/dovecot24&distro=openSUSE%20Tumbleweedpkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3
< 2.3.16-1.6+ 4 more
- (no CPE)range: < 2.3.16-1.6
- (no CPE)range: < 2.4.0-1.1
- (no CPE)range: < 2.2.31-19.8.1
- (no CPE)range: < 2.2.31-19.8.1
- (no CPE)range: < 2.2.31-19.8.1
- The Dovecot Project/Dovecotv5Range: 2.2.33.2
Patches
Vulnerability mechanics
References
7- usn.ubuntu.com/3587-1/nvdPatchThird Party Advisory
- www.securityfocus.com/bid/103201nvdThird Party AdvisoryVDB Entry
- talosintelligence.com/vulnerability_reports/TALOS-2017-0510nvdThird Party Advisory
- www.debian.org/security/2018/dsa-4130nvdThird Party Advisory
- www.dovecot.org/list/dovecot-news/2018-February/000370.htmlnvdIssue TrackingVendor Advisory
- lists.debian.org/debian-lts-announce/2018/03/msg00036.htmlnvd
- usn.ubuntu.com/3587-2/nvd
News mentions
0No linked articles in our index yet.