Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.12 does not properly close old connections, which allows remote attackers to cause a denial of service (resource consumption) via an incomplete SSL/TLS handshake for an IMAP/POP3 connection.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade dovecot | Aug 30, 2017 | May 14, 2014 |
| Centos_linux | — | Upgrade dovecot-develUpgrade dovecot-pgsqlUpgrade dovecot-pigeonholeUpgrade dovecot-mysqlUpgrade dovecot | Dec 1, 2016 | May 14, 2014 |
| Debian | — | Upgrade dovecot | Jul 30, 2024 | May 14, 2014 |
| Gentoo Linux | — | Upgrade net-mail/dovecot. | Oct 30, 2017 | May 14, 2014 |
| Oracle_linux | — | Upgrade dovecot-pgsqlUpgrade dovecot-pigeonholeUpgrade dovecot-develUpgrade dovecotUpgrade dovecot-mysql | Oct 16, 2024 | May 14, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 9, 2014 |
| Suse | — | Upgrade dovecot22-backend-pgsqlUpgrade dovecot22-backend-sqliteUpgrade dovecot22Upgrade dovecot22-develUpgrade dovecot22-backend-mysql | Dec 9, 2016 | May 14, 2014 |
| Ubuntu | — | Upgrade dovecot-coreUpgrade dovecot-imapdUpgrade dovecot-pop3d | Nov 8, 2024 | May 14, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub