VDB
CVE-2011-4318
CVE-2011-4318
PUBLISHED
CVSS 5.800000190734863 MEDIUM
Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.
EPSS 1.32% · 68.7th percentile
Risk Scores
CVSS 2.0
5.800000190734863
EPSS Score
1.32%
68.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| dovecot | dovecot | 2.0.0, 2.0.1, 2.0.2 |
| n/a | n/a | n/a |
Timeline
- Mar 7, 2013 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- RHSA-2013:0520 vendor-advisory
- 46886 third-party-advisory
- https://bugs.gentoo.org/show_bug.cgi?id=390887 url
- https://bugzilla.redhat.com/show_bug.cgi?id=754980 url
- [oss-security] 20111118 Re: CVE Request -- Dovecot -- Validate certificate's CN against requested remote server hostname when proxying mailing-list
- http://hg.dovecot.org/dovecot-2.0/rev/5e9eaf63a6b1 technical
- http://www.dovecot.org/list/dovecot-news/2011-November/000200.html technical
- https://nvd.nist.gov/vuln/detail/CVE-2011-4318 advisory
- http://secunia.com/advisories/52311 url
- http://www.openwall.com/lists/oss-security/2011/11/18/7 url