Debian Security Advisory

DSA-4385-1 dovecot -- security update

Date Reported:
05 Feb 2019
Affected Packages:
dovecot
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2019-3814.
More information:

halfdog discovered an authentication bypass vulnerability in the Dovecot email server. Under some configurations Dovecot mistakenly trusts the username provided via authentication instead of failing. If there is no additional password verification, this allows the attacker to login as anyone else in the system. Only installations using:

  • auth_ssl_require_client_cert = yes
  • auth_ssl_username_from_cert = yes

are affected by this flaw.

For the stable distribution (stretch), this problem has been fixed in version 1:2.2.27-3+deb9u3.

We recommend that you upgrade your dovecot packages.

For the detailed security status of dovecot please refer to its security tracker page at: https://security-tracker.debian.org/tracker/dovecot