CVE-2015-3420
published 2017-09-19CVE-2015-3420: The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash)…
PriorityP424medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
2.84%
85.1th percentile
The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:2.2.13-12 (bookworm) | dovecot 1:2.2.13-12 (bookworm) |
| dovecot | dovecot | <= 2.2.16 | — |
| dovecot | dovecot | >= 0 < 1:2.2.13-12 | 1:2.2.13-12 |
| dovecot | dovecot | >= 0 < 1:2.2.13-12 | 1:2.2.13-12 |
| dovecot | dovecot | >= 0 < 1:2.2.13-12 | 1:2.2.13-12 |
| dovecot | dovecot | >= 0 < 1:2.2.13-12 | 1:2.2.13-12 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dovecot: SSL/TLS handshake failures leading to a crash of the login process.
vendor_redhat·2015-04-26·CVSS 5.9
CVE-2015-3420 [MEDIUM] CWE-391 dovecot: SSL/TLS handshake failures leading to a crash of the login process.
dovecot: SSL/TLS handshake failures leading to a crash of the login process.
The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures.
Statement: This issue did not affect the versions of dovecot as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Package: dovecot (Red Hat Enterprise Linux 5) - Not affected
Package: dovecot (Red Hat Enterprise Linux 6) - Not affected
Package: dovecot (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2015-3420: dovecot - The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disable...
vendor_debian·2015·CVSS 5.9
CVE-2015-3420 [MEDIUM] CVE-2015-3420: dovecot - The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disable...
The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures.
Scope: local
bookworm: resolved (fixed in 1:2.2.13-12)
bullseye: resolved (fixed in 1:2.2.13-12)
forky: resolved (fixed in 1:2.2.13-12)
sid: resolved (fixed in 1:2.2.13-12)
trixie: resolved (fixed in 1:2.2.13-12)
GHSA
GHSA-2h34-774g-95vx: The ssl-proxy-openssl
ghsa_unreviewed·2022-05-17
CVE-2015-3420 [MEDIUM] CWE-295 GHSA-2h34-774g-95vx: The ssl-proxy-openssl
The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures.
OSV
CVE-2015-3420: The ssl-proxy-openssl
osv·2017-09-19·CVSS 5.9
CVE-2015-3420 [MEDIUM] CVE-2015-3420: The ssl-proxy-openssl
The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3420 dovecot: SSL/TLS handshake failures leading to a crash of the login process. [fedora-all]
bugzilla·2015-04-28·CVSS 5.9
CVE-2015-3420 [MEDIUM] CVE-2015-3420 dovecot: SSL/TLS handshake failures leading to a crash of the login process. [fedora-all]
CVE-2015-3420 dovecot: SSL/TLS handshake failures leading to a crash of the login process. [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2015-3420 dovecot: SSL/TLS handshake failures leading to a crash of the login process.
bugzilla·2015-04-28·CVSS 5.9
CVE-2015-3420 [MEDIUM] CVE-2015-3420 dovecot: SSL/TLS handshake failures leading to a crash of the login process.
CVE-2015-3420 dovecot: SSL/TLS handshake failures leading to a crash of the login process.
A flaw was found in the way Dovecot handled SSL handshake failures. A remote attacker could use this flaw to crash the imap-login
and pop3-login processes.
Note that only Dovecot installations accepting SSL/TLS connections that have SSLv3 disabled are vulnerable.
Additional details:
http://dovecot.org/pipermail/dovecot/2015-April/100618.html
http://seclists.org/oss-sec/2015/q2/288
Upstream patch:
http://hg.dovecot.org/dovecot-2.2/rev/86f535375750
Discussion:
Created dovecot tracking bugs for this issue:
Affects: fedora-all [bug 1216059]
---
Steps to reproduce, taken from http://dovecot.org/pipermail/dovecot/2015-April/100618.html:
Add to config: ssl_protocols = !SSLv2 !SSLv3
Run: openssl
arXiv
No Need for Black Chambers: Testing TLS in the E-mail Ecosystem at Large
arxiv_fulltext·2015-11-01
No Need for Black Chambers: Testing TLS in the E-mail Ecosystem at Large
plain
## Abstract
TLS is the most widely used cryptographic protocol on the Internet. While many recent studies focused on its use in HTTPS, none so far analyzed TLS usage in e-mail related protocols, which often carry highly sensitive information. Since end-to-end encryption mechanisms like PGP are seldomly used, today confidentiality in the e-mail ecosystem is mainly based on the encryption of the transport layer. A well-positioned attacker may be able to intercept plaintext passively and at global scale.
In this paper we are the first to present a scalable methodology to assess the state of security mechanisms in the e-mail ecosystem using commodity hardware and open-source software. We draw a comprehensive picture of the current state of every e-mail related TLS configuration for th
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157030.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/158236.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/158261.htmlhttp://www.openwall.com/lists/oss-security/2015/04/27/1http://www.openwall.com/lists/oss-security/2015/04/28/4http://www.securityfocus.com/bid/74335https://bugzilla.redhat.com/show_bug.cgi?id=1216057https://dovecot.org/pipermail/dovecot-news/2015-May/000292.htmlhttps://dovecot.org/pipermail/dovecot/2015-April/100618.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157030.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/158236.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/158261.htmlhttp://www.openwall.com/lists/oss-security/2015/04/27/1http://www.openwall.com/lists/oss-security/2015/04/28/4http://www.securityfocus.com/bid/74335https://bugzilla.redhat.com/show_bug.cgi?id=1216057https://dovecot.org/pipermail/dovecot-news/2015-May/000292.htmlhttps://dovecot.org/pipermail/dovecot/2015-April/100618.html
2017-09-19
Published