A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration where same login processes are reused and can cause the process to crash due to memory exhaustion.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade dovecot | Aug 22, 2024 | Jan 25, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 25, 2018 |
| Debian | — | Upgrade dovecot | Mar 4, 2018 | Jan 25, 2018 |
| Freebsd | — | Upgrade dovecot | Jan 27, 2018 | Jan 26, 2018 |
| Huawei Euleros 2_0_sp1 | — | Upgrade dovecot-pgsqlUpgrade dovecotUpgrade dovecot-pigeonholeUpgrade dovecot-mysql | Mar 16, 2018 | Jan 25, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade dovecot-pgsqlUpgrade dovecotUpgrade dovecot-pigeonholeUpgrade dovecot-mysql | Mar 16, 2018 | Jan 25, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 25, 2018 |
| Suse | — | Upgrade dovecot22-backend-mysqlUpgrade dovecot22Upgrade dovecot23-ftsUpgrade dovecot23-develUpgrade dovecot22-backend-sqliteUpgrade dovecot23-backend-mysqlUpgrade dovecot23-fts-solrUpgrade dovecot23Upgrade dovecot23-fts-luceneUpgrade dovecot23-fts-squatUpgrade dovecot23-backend-pgsqlUpgrade dovecot22-backend-pgsqlUpgrade dovecot22-develUpgrade dovecot23-backend-sqlite | Feb 17, 2018 | Jan 25, 2018 |
| Ubuntu | — | Upgrade dovecot-core | Feb 2, 2018 | Jan 25, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub