CVE-2017-2669
published 2018-06-21CVE-2017-2669: Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the…
PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
4.64%
90.7th percentile
Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending specially crafted %variable fields could result in excessive memory usage causing the process to crash (and restart), or excessive CPU usage causing all authentications to hang.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | dovecot | < dovecot 1:2.2.27-3 (bookworm) | dovecot 1:2.2.27-3 (bookworm) |
| dovecot | dovecot | >= 0 < 1:2.2.27-3 | 1:2.2.27-3 |
| dovecot | dovecot | >= 0 < 1:2.2.27-3 | 1:2.2.27-3 |
| dovecot | dovecot | >= 0 < 1:2.2.27-3 | 1:2.2.27-3 |
| dovecot | dovecot | >= 0 < 1:2.2.27-3 | 1:2.2.27-3 |
| dovecot | dovecot | 2.2.26 – 2.2.28 | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Dovecot regression
vendor_ubuntu·2017-04-11
CVE-2017-2669 Dovecot regression
Title: Dovecot regression
Summary: USN-3258-1 introduced a regression in Dovecot.
USN-3258-1 intended to fix a vulnerability in Dovecot. Further investigation
revealed that only Dovecot versions 2.2.26 and newer were affected by the
vulnerability. Additionally, the change introduced a regression when Dovecot
was configured to use the "dict" authentication database. This update reverts
the change. We apologize for the inconvenience.
Original advisory details:
It was discovered that Dovecot incorrectly handled some usernames. An attacker
could possibly use this issue to cause Dovecot to hang or crash, resulting in a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dovecot: Dovecot DoS when passdb dict was used for authentication
vendor_redhat·2017-04-10·CVSS 3.7
CVE-2017-2669 [LOW] CWE-20 dovecot: Dovecot DoS when passdb dict was used for authentication
dovecot: Dovecot DoS when passdb dict was used for authentication
Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending specially crafted %variable fields could result in excessive memory usage causing the process to crash (and restart), or excessive CPU usage causing all authentications to hang.
Statement: Versions of dovecot shipped in Red Hat Enterprise Linux 5, 6 and 7 are not affected by this vulnerability.
Package: dovecot (Red Hat Enterprise Linux 5) - Not affected
Package: dovecot (Red Hat Enterprise Linux 6) - Not affected
Package: dovecot (Red Hat Enterprise Linux 7) - Not affected
Ubuntu
Dovecot vulnerability
vendor_ubuntu·2017-04-10
CVE-2017-2669 Dovecot vulnerability
Title: Dovecot vulnerability
Summary: Dovecot could be made to crash if it received specially crafted input.
It was discovered that Dovecot incorrectly handled some usernames. An attacker
could possibly use this issue to cause Dovecot to hang or crash, resulting in a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2017-2669: dovecot - Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' ...
vendor_debian·2017·CVSS 3.7
CVE-2017-2669 [LOW] CVE-2017-2669: dovecot - Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' ...
Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending specially crafted %variable fields could result in excessive memory usage causing the process to crash (and restart), or excessive CPU usage causing all authentications to hang.
Scope: local
bookworm: resolved (fixed in 1:2.2.27-3)
bullseye: resolved (fixed in 1:2.2.27-3)
forky: resolved (fixed in 1:2.2.27-3)
sid: resolved (fixed in 1:2.2.27-3)
trixie: resolved (fixed in 1:2.2.27-3)
GHSA
GHSA-qchv-9m57-q82h: Dovecot before version 2
ghsa_unreviewed·2022-05-13
CVE-2017-2669 [HIGH] CWE-20 GHSA-qchv-9m57-q82h: Dovecot before version 2
Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending specially crafted %variable fields could result in excessive memory usage causing the process to crash (and restart), or excessive CPU usage causing all authentications to hang.
OSV
CVE-2017-2669: Dovecot before version 2
osv·2018-06-21·CVSS 7.5
CVE-2017-2669 [HIGH] CVE-2017-2669: Dovecot before version 2
Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending specially crafted %variable fields could result in excessive memory usage causing the process to crash (and restart), or excessive CPU usage causing all authentications to hang.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-14063 async-http-client: Invalid URL parsing with '?'
bugzilla·2017-09-01·CVSS 5.3
CVE-2017-14063 [MEDIUM] CVE-2017-14063 async-http-client: Invalid URL parsing with '?'
CVE-2017-14063 async-http-client: Invalid URL parsing with '?'
Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were previously identified in cURL (CVE-2016-8624) and Oracle Java 8 java.net.URL.
Upstream issue:
https://github.com/AsyncHttpClient/async-http-client/issues/1455
Discussion:
Created async-http-client tracking bugs for this issue:
Affects: fedora-all [bug 1487565]
---
This issue has been addressed in the following products:
Red Hat JBoss Fuse
Via RHSA-2018:2669 https://access.redhat.com/errata/RHSA-2018:2669
Bugzilla
CVE-2017-2669 dovecot: Dovecot DoS when passdb dict was used for authentication [fedora-all]
bugzilla·2017-04-12·CVSS 3.7
CVE-2017-2669 [LOW] CVE-2017-2669 dovecot: Dovecot DoS when passdb dict was used for authentication [fedora-all]
CVE-2017-2669 dovecot: Dovecot DoS when passdb dict was used for authentication [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2017-2669 dovecot: Dovecot DoS when passdb dict was used for authentication
bugzilla·2017-04-04·CVSS 3.7
CVE-2017-2669 [LOW] CVE-2017-2669 dovecot: Dovecot DoS when passdb dict was used for authentication
CVE-2017-2669 dovecot: Dovecot DoS when passdb dict was used for authentication
When "dict" passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending specially crafted %variable fields could result in excessive memory usage causing the process to crash (and restart), or excessive CPU usage causing all authentications to hang.
This issue was introduced by:
https://github.com/dovecot/core/commit/a3783f8a3c9cd816b51e77a922f82301512fcf22
Upstream patch:
https://github.com/dovecot/core/commit/000030feb7a30f193197f1aab8a7b04a26b42735.patch
Vulnerable versions: 2.2.26 - 2.2.28
Discussion:
Acknowledgments:
Name: the Dovecot project
---
According to analysis conducted by Red Hat and
http://www.openwall.com/lists/oss-security/2017/04/11/1http://www.securityfocus.com/bid/97536https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2669https://dovecot.org/pipermail/dovecot-news/2017-April/000341.htmlhttps://github.com/dovecot/core/commit/000030feb7a30f193197f1aab8a7b04a26b42735.patchhttps://www.debian.org/security/2017/dsa-3828http://www.openwall.com/lists/oss-security/2017/04/11/1http://www.securityfocus.com/bid/97536https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2669https://dovecot.org/pipermail/dovecot-news/2017-April/000341.htmlhttps://github.com/dovecot/core/commit/000030feb7a30f193197f1aab8a7b04a26b42735.patchhttps://www.debian.org/security/2017/dsa-3828
2018-06-21
Published