Total vulnerabilities in the database
It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users.
Software | From | Fixed in |
---|---|---|
dovecot / dovecot | 1.1.0 | 2.2.36.1 |
dovecot / dovecot | 2.3.0 | 2.3.4.1 |
canonical / ubuntu_linux | 16.04 | 16.04.x |
canonical / ubuntu_linux | 14.04 | 14.04.x |
canonical / ubuntu_linux | 12.04 | 12.04.x |
canonical / ubuntu_linux | 18.04 | 18.04.x |
canonical / ubuntu_linux | 18.10 | 18.10.x |
opensuse / leap | 42.3 | 42.3.x |