VDB

ALINUX2-SA-2020%3A0076

ALINUX2-SA-2020%3A0076 PUBLISHED CVSS 7.699999809265137 HIGH

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2019-3814: It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users. CVE-2019-7524: In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to root. This occurs because of missing checks in the fts and pop3-uidl components.

Risk Scores

CVSS 3.0
7.699999809265137
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N

Affected Products

VendorProductVersions
Alibaba Clouddovecot

Timeline

  • Apr 3, 2020 CVE Published
  • Apr 3, 2020 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›