vulnerability

Arch Linux: Information disclosure (CVE-2017-14461)

Severity
5
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:P)
Published
Mar 2, 2018
Added
Jul 11, 2025
Modified
Nov 27, 2025

Description

A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure of an email from another user or may cause an application crash. In order to trigger this vulnerability, an imap-authenticated attacker needs to send a specially crafted email message to the server.

Solution

arch-linux-upgrade-latest

References

    Title
    NEW

    Explore Exposure Command

    Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.