CVE-2019-3814: High severity Dovecot dovecot vulnerability
It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users.
Other sources
It was discovered that Dovecot incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users.
References: https://security-tracker.debian.org/tracker/source-package/dovecot https://usn.ubuntu.com/usn/usn-3881-1 https://usn.ubuntu.com/usn/usn-3881-2
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/dovecotto a version that resolves this vulnerability.Fixed in 2.2.36.1 - Upgrade
Upgrade
redhat/dovecotto a version that resolves this vulnerability.Fixed in 2.3.4.1 - Upgrade
Upgrade
debian/dovecotto a version that resolves this vulnerability.Fixed in 1:2.3.13+dfsg1-2+deb11u1Fixed in 1:2.3.13+dfsg1-2+deb11u4Fixed in 1:2.3.19.1+dfsg1-2.1+deb12u6Fixed in 1:2.4.1+dfsg1-6+deb13u6Fixed in 1:2.4.4+dfsg1-2 - Upgrade
Upgrade
dovecotto a version that resolves this vulnerability.Fixed in 2.2.36.1 - Upgrade
Upgrade
dovecotto a version that resolves this vulnerability.Fixed in 2.3.4.1
Event History
Frequently Asked Questions
What is CVE-2019-3814?
CVE-2019-3814 is a vulnerability in Dovecot that incorrectly handles client certificates, allowing a remote attacker to impersonate other users.
What is the severity of CVE-2019-3814?
The severity of CVE-2019-3814 is high, with a severity value of 6.8.
How does CVE-2019-3814 affect Dovecot?
CVE-2019-3814 affects Dovecot versions 2.2.36.1 and 2.3.4.1.
How can an attacker exploit CVE-2019-3814?
An attacker in possession of a valid certificate with an empty username field can exploit CVE-2019-3814 to impersonate other users.
Are there any remedies available for CVE-2019-3814?
Yes, updating to Dovecot versions 2.2.36.1 or 2.3.4.1 can fix CVE-2019-3814.