RULE(RULE ID:405129)

Rule General Information
Release Date: 2017-09-14
Rule Name: PROTOCOL-IMAP Dovecot SASL Authentication Component Denial of Service Vulnerability -4 (CVE-2016-8652)
Severity:
CVE ID:
Rule Protection Details
Description: The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authentication without setting a username.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Mac OS, Solaris, Other Unix, FreeBSD, Linux
Reference: CVE-2016-8652
Solutions
Upgrading to 2.2.27 and later version to resolve the problem.