Amazon Linux AMI : dovecot (ALAS-2014-386)
Medium Nessus Plugin ID 78329
SynopsisThe remote Amazon Linux AMI host is missing a security update.
DescriptionDovecot 1.1 before 2.2.13 and dovecot-ee before 126.96.36.199 and 2.2.x before 188.8.131.52 does not properly close old connections, which allows remote attackers to cause a denial of service (resource consumption) via an incomplete SSL/TLS handshake for an IMAP/POP3 connection.
SolutionRun 'yum update dovecot' to update your system.