PT-2019-1772 · Dovecot+5 · Dovecot+5

Halfdog

·

Publicado

2019-02-05

·

Atualizado

2025-01-30

·

CVE-2019-3814

CVSS v3.1

7.7

Alta

VetorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Dovecot versions prior to 2.2.36.1 Dovecot versions prior to 2.3.4.1
Description The issue is related to errors in certificate authentication. A remote attacker with a valid certificate that has an empty username field could potentially use this to impersonate other users. This could allow an unauthorized access to protected information.
Recommendations For versions prior to 2.2.36.1, update to version 2.2.36.1 or later. For versions prior to 2.3.4.1, update to version 2.3.4.1 or later.

Exploit

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1512
BDU:2019-01416
CESA-2019_3467
CESA-2020_1062
CVE-2019-3814
DLA-1667-1
DSA-4385-1
MGASA-2019-0072
OPENSUSE-SU-2019:0243-1
OPENSUSE-SU-2019_0243-1
OPENSUSE-SU-2019_1220-1
OPENSUSE-SU-2024:10726-1
OPENSUSE-SU-2025:14715-1
RHSA-2019:3467
RHSA-2019_3467
RHSA-2020:1062
RHSA-2020_1062
SUSE-SU-2019:0414-1
SUSE-SU-2019:0900-1
SUSE-SU-2019_0414-1
SUSE-SU-2019_0900-1
USN-3881-1
USN-3881-2

Produtos afetados

Alt Linux
Centos
Dovecot
Red Hat
Suse
Ubuntu