Описание
The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.
A flaw was found in dovecot. The comparison mechanism for doveadm passwords and API keys is not fully timing safe. A remote attacker, with network access to the doveadm service, could repeatedly make requests and accurately measure response timings. This could allow the attacker to learn the length of the configured secret, which reduces the effort needed to guess the secret value. The secret value itself is not directly disclosed by this vulnerability.
Меры по смягчению последствий
To mitigate this issue, restrict network access to the doveadm service to only trusted clients. This can be achieved by configuring firewall rules to limit inbound connections to the doveadm service's port from known, secure IP addresses or subnets. Consult your system's firewall documentation (e.g., firewalld or iptables) for specific configuration steps.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | dovecot | Fix deferred | ||
| Red Hat Enterprise Linux 6 | dovecot | Out of support scope | ||
| Red Hat Enterprise Linux 7 | dovecot | Fix deferred | ||
| Red Hat Enterprise Linux 8 | dovecot | Fix deferred | ||
| Red Hat Enterprise Linux 9 | dovecot | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
3.1 Low
CVSS3
Связанные уязвимости
The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.
The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.
The comparison used for the doveadm password and API key is not fully ...
The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.
EPSS
3.1 Low
CVSS3