Debian Security Advisory

DLA-0004-1 dovecot -- LTS security update

Date Reported:
11 Jun 2014
Affected Packages:
dovecot
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 747549.
In Mitre's CVE dictionary: CVE-2014-3430.
More information:

It was discovered that the Dovecot email server is vulnerable to a denial of service attack against imap/pop3-login processes due to incorrect handling of the closure of inactive SSL/TLS connections.

For Debian 6 Squeeze, these issues have been fixed in dovecot version 1:1.2.15-7+deb6u1