Lucene search

K
redhatcveRedhat.comRH:CVE-2019-3814
HistoryFeb 07, 2019 - 1:49 p.m.

CVE-2019-3814

2019-02-0713:49:38
redhat.com
access.redhat.com
15

EPSS

0.003

Percentile

69.4%

It was discovered that Dovecot incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users.

Mitigation

Attack can be migitated by having the certificates with proper Extended Key Usage, such as 'TLS Web Server' and 'TLS Web Server Client'. Also client-side certification authentication can be turned off using:
auth_ssl_require_client_cert = no
auth_ssl_username_from_cert = no