Lucene search

K
redhatcveRedhat.comRH:CVE-2020-12674
HistoryAug 13, 2020 - 4:13 a.m.

CVE-2020-12674

2020-08-1304:13:37
redhat.com
access.redhat.com
11

0.003 Low

EPSS

Percentile

69.7%

A flaw was found in dovecot. An attacker can use the way dovecot handles RPA (Remote Passphrase Authentication) to crash the authentication process repeatedly preventing login. The highest threat from this vulnerability is to system availability.

Mitigation

Upstream suggests that this flaw can be mitigated by disabling RPA (Remote Passphrase Authentication). RPA can be disabled by using the configuration parameter "auth_mechanisms". More details available at: <https://doc.dovecot.org/configuration_manual/authentication/authentication_mechanisms/&gt;