Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-20790

Опубликовано: 27 апр. 2020
Источник: debian
EPSS Низкий

Описание

OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opendmarcfixed1.4.0~beta1+dfsg-4package
opendmarcno-dsabusterpackage
opendmarcno-dsastretchpackage

Примечания

  • https://bugs.launchpad.net/pypolicyd-spf/+bug/1838816

  • https://sourceforge.net/p/opendmarc/tickets/235/

  • https://www.usenix.org/system/files/sec20fall_chen-jianjun_prepub_0.pdf

  • Issue is disputed upstream and considered "work as designed" (wontfix)

  • https://github.com/trusteddomainproject/OpenDMARC/blob/develop/SECURITY/CVE-2019-20790

  • Upstream reconsidering position:

  • https://github.com/trusteddomainproject/OpenDMARC/issues/158

EPSS

Процентиль: 45%
0.00226
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 6 лет назад

OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.

CVSS3: 9.8
nvd
почти 6 лет назад

OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.

CVSS3: 9.8
github
больше 3 лет назад

OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.

EPSS

Процентиль: 45%
0.00226
Низкий