CVE-2019-3814

Publication date 5 February 2019

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

6.8 · Medium

Score breakdown

It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users.

Status

Package Ubuntu Release Status
dovecot 18.10 cosmic
Fixed 1:2.3.2.1-1ubuntu3.1
18.04 LTS bionic
Fixed 1:2.2.33.2-1ubuntu4.2
16.04 LTS xenial
Fixed 1:2.2.22-1ubuntu2.9
14.04 LTS trusty
Fixed 1:2.2.9-1ubuntu2.5

Severity score breakdown

Parameter Value
Base score 6.8 · Medium
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact None
Vector CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

References

Related Ubuntu Security Notices (USN)

Other references