{
  "threat_severity" : "Moderate",
  "public_date" : "2018-02-28T00:00:00Z",
  "bugzilla" : {
    "description" : "dovecot: Information Leak Vulnerability in rfc822_parse_domain leading to denial-of-service",
    "id" : "1549483",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1549483"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.9",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H",
    "status" : "draft"
  },
  "cwe" : "CWE-200",
  "details" : [ "A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vulnerability, an attacker needs to send a specially crafted email message to the server." ],
  "acknowledgement" : "Red Hat would like to thank the Dovecot project for reporting this issue. Upstream acknowledges Aleksandar Nikolic (Cisco Talos) and flxflndy as the original reporters.",
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 5",
    "fix_state" : "Not affected",
    "package_name" : "dovecot",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Affected",
    "package_name" : "dovecot",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Affected",
    "package_name" : "dovecot",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "dovecot",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2017-14461\nhttps://nvd.nist.gov/vuln/detail/CVE-2017-14461\nhttps://www.dovecot.org/list/dovecot-news/2018-February/000370.html\nhttps://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0510" ],
  "name" : "CVE-2017-14461",
  "csaw" : false
}