ASA-201705-1 generated external raw

[ASA-201705-1] dovecot: denial of service
Arch Linux Security Advisory ASA-201705-1 ========================================= Severity: Medium Date : 2017-05-01 CVE-ID : CVE-2017-2669 Package : dovecot Type : denial of service Remote : Yes Link : https://security.archlinux.org/AVG-238 Summary ======= The package dovecot before version 2.2.29.1-1 is vulnerable to denial of service. Resolution ========== Upgrade to 2.2.29.1-1. # pacman -Syu "dovecot>=2.2.29.1-1" The problem has been fixed upstream in version 2.2.29.1. Workaround ========== None. Description =========== A security issue has been found in Dovecot >= 2.2.26 and <= 2.2.28. If the "dict" passdb is used for authentication, the username sent by the client is passed to the var_expand() function and double expansion of %-variables is performed. A remote unauthenticated attacker could then send a specially crafted username containing %variables to cause a denial of service. Impact ====== A remote, unauthenticated attacker can cause a denial of service by sending a specially crafted username. References ========== https://dovecot.org/list/dovecot-news/2017-April/000341.html https://github.com/dovecot/core/commit/000030feb7a30f193197f1aab8a7b04a26b42735.patch https://security.archlinux.org/CVE-2017-2669