Debian Security Advisory
DSA-4385-1 dovecot -- security update
- Date Reported:
- 05 Feb 2019
- Affected Packages:
- Security database references:
- In Mitre's CVE dictionary: CVE-2019-3814.
- More information:
halfdog discovered an authentication bypass vulnerability in the Dovecot email server. Under some configurations Dovecot mistakenly trusts the username provided via authentication instead of failing. If there is no additional password verification, this allows the attacker to login as anyone else in the system. Only installations using:
- auth_ssl_require_client_cert = yes
- auth_ssl_username_from_cert = yes
are affected by this flaw.
For the stable distribution (stretch), this problem has been fixed in version 1:2.2.27-3+deb9u3.
We recommend that you upgrade your dovecot packages.
For the detailed security status of dovecot please refer to its security tracker page at: https://security-tracker.debian.org/tracker/dovecot