← Voltar para CVEs
CVE-2019-3814
N/ADescricao
It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users.
Detalhes CVE
Pontuacao CVSS v3.1N/A
Publicado3/27/2019
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
canonical:ubuntu_linuxdovecot:dovecotopensuse:leap
Fraquezas (CWE)
CWE-295CWE-295
Referencias
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00067.html(secalert@redhat.com)
https://access.redhat.com/errata/RHSA-2019:3467(secalert@redhat.com)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3814(secalert@redhat.com)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4XLI55NGRDTGMVOPYFCPPFNPA5VKYSSY/(secalert@redhat.com)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QHFZ5OWRIZGIWZJ5PTNVWWZNLLNH4XYS/(secalert@redhat.com)
https://security.gentoo.org/glsa/201904-19(secalert@redhat.com)
https://www.dovecot.org/list/dovecot/2019-February/114575.html(secalert@redhat.com)
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00067.html(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:3467(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3814(af854a3a-2127-422b-91ae-364da2661108)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4XLI55NGRDTGMVOPYFCPPFNPA5VKYSSY/(af854a3a-2127-422b-91ae-364da2661108)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QHFZ5OWRIZGIWZJ5PTNVWWZNLLNH4XYS/(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/201904-19(af854a3a-2127-422b-91ae-364da2661108)
https://www.dovecot.org/list/dovecot/2019-February/114575.html(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.