Medium severity5.9NVD Advisory· Published Mar 2, 2018· Updated Jun 17, 2026
CVE-2017-15130
CVE-2017-15130
Description
A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
21cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*range: <2.2.34
- (no CPE)range: <2.2.34
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
- osv-coords13 versionspkg:rpm/opensuse/dovecot23&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/dovecot24&distro=openSUSE%20Tumbleweedpkg:rpm/suse/dovecot22&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/dovecot22&distro=SUSE%20OpenStack%20Cloud%207
< 2.3.16-1.6+ 12 more
- (no CPE)range: < 2.3.16-1.6
- (no CPE)range: < 2.4.0-1.1
- (no CPE)range: < 2.2.31-19.11.1
- (no CPE)range: < 2.2.31-19.11.1
- (no CPE)range: < 2.2.31-19.11.1
- (no CPE)range: < 2.2.31-19.11.1
- (no CPE)range: < 2.2.31-19.11.1
- (no CPE)range: < 2.2.31-19.11.1
- (no CPE)range: < 2.2.31-19.11.1
- (no CPE)range: < 2.2.31-19.11.1
- (no CPE)range: < 2.2.31-19.11.1
- (no CPE)range: < 2.2.31-19.11.1
- (no CPE)range: < 2.2.31-19.11.1
- The Dovecot Project/dovecotv5Range: before 2.2.34
Patches
Vulnerability mechanics
References
7- seclists.org/oss-sec/2018/q1/205nvdMailing ListThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- usn.ubuntu.com/3587-1/nvdThird Party Advisory
- www.debian.org/security/2018/dsa-4130nvdThird Party Advisory
- www.dovecot.org/list/dovecot-news/2018-February/000370.htmlnvdRelease NotesVendor Advisory
- lists.debian.org/debian-lts-announce/2018/03/msg00036.htmlnvd
- usn.ubuntu.com/3587-2/nvd
News mentions
0No linked articles in our index yet.