|
|||
Rule General Information |
---|
Release Date: | 2017-09-14 | |
Rule Name: | PROTOCOL-IMAP Dovecot SASL Authentication Component Denial of Service Vulnerability -4 (CVE-2016-8652) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authentication without setting a username. | |
Impact: | An attacker can launch a denial of service attack by exploiting the vulnerability successfully. | |
Affected OS: | Mac OS, Solaris, Other Unix, FreeBSD, Linux | |
Reference: | CVE-2016-8652 |
|
Solutions |
---|
Upgrading to 2.2.27 and later version to resolve the problem. |