Red Hat Bugzilla – Bug 1532356
CVE-2017-15130 dovecot: TLS SNI config lookups are inefficient and can be used for DoS
Last modified: 2018-08-31 17:53:57 EDT
TLS SNI config lookups may lead to excessive memory usage, causing imap-login/pop3-login VSZ limit to be reached and the process restarted. This happens only if Dovecot config has local_name { } or local { } configuration blocks and attacker uses randomly generated SNI servernames.
Acknowledgments: Name: The Dovecot Project
Reference: http://www.openwall.com/lists/oss-security/2018/03/01/3
External References: https://www.dovecot.org/list/dovecot-news/2018-February/000370.html