Executive Summary
Summary | |
---|---|
Title | dovecot security update |
Informations | |||
---|---|---|---|
Name | DSA-4385 | First vendor Publication | 2019-02-05 |
Vendor | Debian | Last vendor Modification | 2019-02-05 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : | |||
---|---|---|---|
Cvss Base Score | N/A | Attack Range | N/A |
Cvss Impact Score | N/A | Attack Complexity | N/A |
Cvss Expoit Score | N/A | Authentication | N/A |
Calculate full CVSS 2.0 Vectors scores |
Detail
halfdog discovered an authentication bypass vulnerability in the Dovecot email server. Under some configurations Dovecot mistakenly trusts the username provided via authentication instead of failing. If there is no additional password verification, this allows the attacker to login as anyone else in the system. Only installations using: auth_ssl_require_client_cert = yes auth_ssl_username_from_cert = yes are affected by this flaw. For the stable distribution (stretch), this problem has been fixed in version 1:2.2.27-3+deb9u3. We recommend that you upgrade your dovecot packages. For the detailed security status of dovecot please refer to its security tracker page at: https://security-tracker.debian.org/tracker/dovecot |
Original Source
Url : http://www.debian.org/security/2019/dsa-4385 |
Alert History
Date | Informations |
---|---|
2019-02-05 21:18:37 |
|