What the vulnerability does

01Description

A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart.

Key dates

02Disclosure timeline

March 2, 2018 CVE published
September 16, 2024 Record updated

Related vulnerabilities

04Related CVE