Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3814

Опубликовано: 05 фев. 2019
Источник: redhat
CVSS3: 7.7
EPSS Низкий

Описание

It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users.

It was discovered that Dovecot incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users.

Меры по смягчению последствий

Attack can be migitated by having the certificates with proper Extended Key Usage, such as 'TLS Web Server' and 'TLS Web Server Client'. Also client-side certification authentication can be turned off using: auth_ssl_require_client_cert = no auth_ssl_username_from_cert = no

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dovecotWill not fix
Red Hat Enterprise Linux 6dovecotWill not fix
Red Hat Enterprise Linux 7dovecotFixedRHSA-2020:106231.03.2020
Red Hat Enterprise Linux 8dovecotFixedRHSA-2019:346705.11.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=1673415dovecot: Improper certificate validation

EPSS

Процентиль: 64%
0.00487
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
больше 6 лет назад

It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users.

CVSS3: 7.7
nvd
больше 6 лет назад

It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users.

CVSS3: 7.7
debian
больше 6 лет назад

It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 in ...

suse-cvrf
больше 6 лет назад

Security update for dovecot23

suse-cvrf
больше 6 лет назад

Security update for dovecot23

EPSS

Процентиль: 64%
0.00487
Низкий

7.7 High

CVSS3