[ASA-201705-1] dovecot: denial of service
Arch Linux Security Advisory ASA-201705-1 ========================================= Severity: Medium Date : 2017-05-01 CVE-ID : CVE-2017-2669 Package : dovecot Type : denial of service Remote : Yes Link : Summary ======= The package dovecot before version is vulnerable to denial of service. Resolution ========== Upgrade to # pacman -Syu "dovecot>=" The problem has been fixed upstream in version Workaround ========== None. Description =========== A security issue has been found in Dovecot >= 2.2.26 and <= 2.2.28. If the "dict" passdb is used for authentication, the username sent by the client is passed to the var_expand() function and double expansion of %-variables is performed. A remote unauthenticated attacker could then send a specially crafted username containing %variables to cause a denial of service. Impact ====== A remote, unauthenticated attacker can cause a denial of service by sending a specially crafted username. References ==========