GCVE-VVD-MAGEIA-2019-72
Advisory Published
Vulnetix · Advisory published July 25, 2019
CVE-2019-3814: If imap/pop3/managesieve/submission client has trusted certificate with missing username field (ssl_cert_username_field), under some configurations Dovecot mistakenly trusts the username provided via authentication instead of failing.

Affected Products

VendorProductVersionsPlatforms
Mageiaflash-player-plugin0 (affected), 32.0.0.223-1.mga7.nonfree (unaffected)
Mageiadovecot0 (affected), 2.2.36.1-1.mga6 (unaffected), 0 (affected), 2.2.36.1-1.mga6 (unaffected)
Mageiaflash-player-plugin0 (affected), 32.0.0.223-1.mga6.nonfree (unaffected)

References

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.