PT-2019-1772 · Dovecot+5 · Dovecot+5

Halfdog

·

Published

2019-02-05

·

Updated

2025-01-30

·

CVE-2019-3814

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Dovecot versions prior to 2.2.36.1 Dovecot versions prior to 2.3.4.1
Description The issue is related to errors in certificate authentication. A remote attacker with a valid certificate that has an empty username field could potentially use this to impersonate other users. This could allow an unauthorized access to protected information.
Recommendations For versions prior to 2.2.36.1, update to version 2.2.36.1 or later. For versions prior to 2.3.4.1, update to version 2.3.4.1 or later.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1512
BDU:2019-01416
CESA-2019_3467
CESA-2020_1062
CVE-2019-3814
DLA-1667-1
DSA-4385-1
MGASA-2019-0072
OPENSUSE-SU-2019:0243-1
OPENSUSE-SU-2019_0243-1
OPENSUSE-SU-2019_1220-1
OPENSUSE-SU-2024:10726-1
OPENSUSE-SU-2025:14715-1
RHSA-2019:3467
RHSA-2019_3467
RHSA-2020:1062
RHSA-2020_1062
SUSE-SU-2019:0414-1
SUSE-SU-2019:0900-1
SUSE-SU-2019_0414-1
SUSE-SU-2019_0900-1
USN-3881-1
USN-3881-2

Affected Products

Alt Linux
Centos
Dovecot
Red Hat
Suse
Ubuntu