Fedora 22 : dovecot-2.2.16-2.fc22 (2015-7156)

medium Nessus Plugin ID 83223

Synopsis

The remote Fedora host is missing a security update.

Description

fixes CVE-2015-3420: SSL/TLS handshake failures leading to a crash of the login process

- dovecot updated to 2.2.16

- auth: Don't crash if master user login is attempted without any configured master=yes passdbs

- Parsing UTF-8 text for mails could have caused broken results sometimes if buffering was split in the middle of a UTF-8 character. This affected at least searching messages.

- String sanitization for some logged output wasn't done properly: UTF-8 text could have been truncated wrongly or the truncation may not have happened at all.

- fts-lucene: Lookups from virtual mailbox consisting of over 32 physical mailboxes could have caused crashes.

- dovecot updated to 2.2.16

- auth: Don't crash if master user login is attempted without any configured master=yes passdbs

- Parsing UTF-8 text for mails could have caused broken results sometimes if buffering was split in the middle of a UTF-8 character. This affected at least searching messages.

- String sanitization for some logged output wasn't done properly: UTF-8 text could have been truncated wrongly or the truncation may not have happened at all.

- fts-lucene: Lookups from virtual mailbox consisting of over 32 physical mailboxes could have caused crashes.

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected dovecot package.

See Also

https://bugzilla.redhat.com/show_bug.cgi?id=1216057

http://www.nessus.org/u?4bdd5fd6

Plugin Details

Severity: Medium

ID: 83223

File Name: fedora_2015-7156.nasl

Version: 2.5

Type: local

Agent: unix

Published: 5/4/2015

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:dovecot, cpe:/o:fedoraproject:fedora:22

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 4/29/2015

Reference Information

CVE: CVE-2015-3420

FEDORA: 2015-7156