CVE-2013-2111
Publication date 27 May 2014
Last updated 24 July 2024
Ubuntu priority
The IMAP functionality in Dovecot before 2.2.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via invalid APPEND parameters.
Status
Package | Ubuntu Release | Status |
---|---|---|
dovecot | 14.04 LTS trusty |
Not affected
|
Notes
seth-arnold
"low" because after authentication a user can cause their own process to spin; there are per-(user,IP) connection limits to limit the slowdown.
mdeslaur
only seems to affect 2.2.x
Patch details
Package | Patch details |
---|---|
dovecot |