Executive Summary

Informations
Name MDVSA-2010:104 First vendor Publication 2010-05-21
Vendor Mandriva Last vendor Modification 2010-05-21
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Cvss Base Score 5 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

A vulnerability was discovered and corrected in dovecot:

Unspecified vulnerability in Dovecot 1.2.x before 1.2.11 allows remote attackers to cause a denial of service (CPU consumption) via long headers in an e-mail message (CVE-2010-0745).

This update provides dovecot 1.2.11 which is not vulnerable to this issue and also holds many bugfixes as well.

Original Source

Url : http://www.mandriva.com/security/advisories?name=MDVSA-2010:104

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-399 Resource Management Errors

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 11

OpenVAS Exploits

Date Description
2012-02-12 Name : Gentoo Security Advisory GLSA 201110-04 (Dovecot)
File : nvt/glsa_201110_04.nasl
2010-05-28 Name : Mandriva Update for dovecot MDVSA-2010:104 (dovecot)
File : nvt/gb_mandriva_MDVSA_2010_104.nasl
2010-03-22 Name : Mandriva Update for iptables MDVA-2010:104 (iptables)
File : nvt/gb_mandriva_MDVA_2010_104.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
64783 Dovecot E-mail Message Header Unspecified DoS

Nessus® Vulnerability Scanner

Date Description
2011-10-11 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201110-04.nasl - Type : ACT_GATHER_INFO
2010-07-30 Name : The remote Mandriva Linux host is missing one or more security updates.
File : mandriva_MDVSA-2010-104.nasl - Type : ACT_GATHER_INFO
2010-04-29 Name : The remote openSUSE host is missing a security update.
File : suse_11_2_dovecot12-100426.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2014-02-17 11:41:29
  • Multiple Updates