Security Advisory

CVE-2011-4318

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2013-03-07 01:00:00
Last updated 2024-08-07 00:01:51
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.