Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.
CVSS Details
- CVSS 3.1 Base Score: 4.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade dovecot-pgsqlUpgrade dovecot-develUpgrade dovecotUpgrade dovecot-pigeonholeUpgrade dovecot-mysql | Dec 1, 2016 | Mar 6, 2013 |
| Debian | — | Upgrade dovecot | Jul 30, 2024 | Mar 7, 2013 |
| Oracle_linux | — | Upgrade dovecot-pgsqlUpgrade dovecot-mysqlUpgrade dovecotUpgrade dovecot-pigeonholeUpgrade dovecot-devel | Oct 16, 2024 | Mar 7, 2013 |
| Suse | — | Upgrade dovecot20-backend-mysqlUpgrade dovecot20-debuginfoUpgrade dovecot20-develUpgrade dovecot20-backend-sqlite-debuginfoUpgrade dovecot20-backend-pgsql-debuginfoUpgrade dovecot20-backend-mysql-debuginfoUpgrade dovecot20-fts-solrUpgrade dovecot20-backend-pgsqlUpgrade dovecot20-backend-sqliteUpgrade dovecot20Upgrade dovecot20-fts-solr-debuginfoUpgrade dovecot20-debugsource | Dec 12, 2013 | Mar 6, 2013 |
| Ubuntu | — | Upgrade dovecot-common | Nov 8, 2024 | Mar 7, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub