MGASA-2019-0072

Source
https://advisories.mageia.org/MGASA-2019-0072.html
Import Source
https://advisories.mageia.org/MGASA-2019-0072.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2019-0072
Related
Published
2019-02-13T11:08:25Z
Modified
2019-02-13T10:38:35Z
Summary
Updated dovecot packages fix security vulnerability
Details

CVE-2019-3814: If imap/pop3/managesieve/submission client has trusted certificate with missing username field (sslcertusername_field), under some configurations Dovecot mistakenly trusts the username provided via authentication instead of failing.

References
Credits

Affected packages