{"affected":[{"ecosystem_specific":{"binaries":[{"dovecot22":"2.2.31-19.5.1","dovecot22-backend-mysql":"2.2.31-19.5.1","dovecot22-backend-pgsql":"2.2.31-19.5.1","dovecot22-backend-sqlite":"2.2.31-19.5.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2","name":"dovecot22","purl":"pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.2.31-19.5.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"dovecot22-devel":"2.2.31-19.5.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP2","name":"dovecot22","purl":"pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.2.31-19.5.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"dovecot22-devel":"2.2.31-19.5.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP3","name":"dovecot22","purl":"pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.2.31-19.5.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"dovecot22":"2.2.31-19.5.1","dovecot22-backend-mysql":"2.2.31-19.5.1","dovecot22-backend-pgsql":"2.2.31-19.5.1","dovecot22-backend-sqlite":"2.2.31-19.5.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP2","name":"dovecot22","purl":"pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.2.31-19.5.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"dovecot22":"2.2.31-19.5.1","dovecot22-backend-mysql":"2.2.31-19.5.1","dovecot22-backend-pgsql":"2.2.31-19.5.1","dovecot22-backend-sqlite":"2.2.31-19.5.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP2","name":"dovecot22","purl":"pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.2.31-19.5.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"dovecot22":"2.2.31-19.5.1","dovecot22-backend-mysql":"2.2.31-19.5.1","dovecot22-backend-pgsql":"2.2.31-19.5.1","dovecot22-backend-sqlite":"2.2.31-19.5.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP3","name":"dovecot22","purl":"pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.2.31-19.5.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"dovecot22":"2.2.31-19.5.1","dovecot22-backend-mysql":"2.2.31-19.5.1","dovecot22-backend-pgsql":"2.2.31-19.5.1","dovecot22-backend-sqlite":"2.2.31-19.5.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP3","name":"dovecot22","purl":"pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.2.31-19.5.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for dovecot22 fixes one issue.\n\nThis security issue was fixed:\n\n- CVE-2017-15132: An abort of SASL authentication resulted in a memory leak in\n  dovecot's auth client used by login processes. The leak has impact in high\n  performance configuration where same login processes are reused and can cause\n  the process to crash due to memory exhaustion (bsc#1075608).\n","id":"SUSE-SU-2018:0466-1","modified":"2018-02-16T14:59:05Z","published":"2018-02-16T14:59:05Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20180466-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1075608"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-15132"}],"related":["CVE-2017-15132"],"summary":"Security update for dovecot22","upstream":["CVE-2017-15132"]}