﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
6444	Dovecot-2.2.16 Security Issue: CVE-2015-3420	Fernando de Oliveira	Fernando de Oliveira	"[http://www.shieldjournal.com/dovecot-remote-tls-dos-cve-2015-3420/]

{{{
The latest release of the Dovecot IMAP server (2.2.16) is vulnerable
to a remote denial of service (DoS) and has been assigned CVE-2015-3420.
}}}


[https://cxsecurity.com/issue/WLB-2015040183]

{{{
The current Dovecot (2.2.16) imap/pop3 server has an issue that
handshake failures will lead to a crash of the login process.
}}}

Patch:

{{{
*-login: Don't try to flush SSL output if SSL handshake fails.
This fixes a crash on failed handshakes on some OpenSSL builds.
}}}

[http://hg.dovecot.org/dovecot-2.2/raw-diff/86f535375750/src/login-common/ssl-proxy-openssl.c]

Think we should fix the book. Please, someone could confirm and take this ticket?

Thanks"	defect	closed	high	7.8	BOOK	SVN	medium	fixed		
