Atakujący może wykorzystać specjalnie przygotowaną wymianę base64 między Dovecot a klientem, aby sfałszować SCRAM TLS channel binding. Wymaga to umożliwienia atakującemu pozycjonowania się między Dovecot a połączeniem klienta. W przypadku powodzenia atakujący może podsłuchiwać komunikację między Dovecot a klientem jako proxy MITM. Zainstaluj naprawioną wersję. Nie znane są publicznie dostępne exploity.
▸ Pokaż oryginał (EN)
Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NDovecot
APPDovecot< 2.4.4Open Xchange Dovecot
APPOpen-Xchange< 3.1.5
Powiązane podatności
Dovecot/Pigeonhole: RCE przez błędną obsługę znaków null w łańcuchach
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly i...
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerabil...
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to cras...
Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An atta...