Wind River Support Network

Meet the Support Network

Home CVE Database CVE-2017-15132

CVE-2017-15132

Description

A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot\'s auth client used by login processes. The leak has impact in high performance configuration where same login processes are reused and can cause the process to crash due to memory exhaustion.

Priority: MEDIUM
CVSS v3: 7.5
Component: dovecot
Publish Date: Jan 25, 2018
Related ID: --
CVSS v2: High
Modified Date: Jan 25, 2018

Find out more about CVE-2017-15132 from the MITRE-CVE dictionary and NIST NVD


Products Affected

Login may be required to access defects or downloads.

Product Name Status Defect Fixed Downloads
Linux
Wind River Linux LTS 17 Won't Fix -- -- --
Wind River Linux 8 Fixed LIN8-8626
8.0.0.25 --
Wind River Linux 9 Fixed LIN9-6282
9.0.0.15 --
Wind River Linux 7 Fixed -- 7.0.0.28 --
Wind River Linux LTS 21 Won't Fix -- -- --
Wind River Linux LTS 22 Won't Fix -- -- --
Wind River Linux LTS 18 Won't Fix -- -- --
Wind River Linux LTS 19 Won't Fix -- -- --
Wind River Linux CD release Won't Fix -- -- --
Wind River Linux 6 Not Vulnerable -- -- --
Wind River Linux LTS 23 Won't Fix -- -- --
Wind River Linux LTS 24 Won't Fix -- -- --
VxWorks
VxWorks 7 Not Vulnerable -- -- --
VxWorks 6.9 Not Vulnerable -- -- --
Helix Virtualization Platform Cert Edition
Helix Virtualization Platform Cert Edition Not Vulnerable -- -- --
eLxr
eLxr 12 Not Vulnerable -- -- --
Wind River Studio Cloud Platform

Related Products

Product Name Status Defect Fixed Downloads

Notes
Requires LTSS - customers must have active LTSS (Long Term Security Shield) Support to receive up-to-date information about vulnerabilities that may affect legacy software. Please contact your Wind River account team or see https://docs.windriver.com/bundle/Support_and_Maintenance_Supplemental_Terms_and_Conditions and https://support2.windriver.com/index.php?page=plc for more information.
Live chat
Online