Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-12272

Опубликовано: 27 апр. 2020
Источник: debian
EPSS Низкий

Описание

OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the example.net(.example.com substring.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opendmarcfixed1.4.0~beta1+dfsg-4package
opendmarcpostponedstretchpackage

Примечания

  • https://sourceforge.net/p/opendmarc/tickets/237/

  • https://www.usenix.org/system/files/sec20fall_chen-jianjun_prepub_0.pdf

  • Fix: https://github.com/trusteddomainproject/OpenDMARC/commit/f3a9a9d4edfaa05102292727d021683f58aa4b6e

EPSS

Процентиль: 74%
0.00806
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 6 лет назад

OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the example.net(.example.com substring.

CVSS3: 5.3
nvd
почти 6 лет назад

OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the example.net(.example.com substring.

CVSS3: 5.3
github
больше 3 лет назад

OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the example.net(.example.com substring.

CVSS3: 5.3
fstec
почти 6 лет назад

Уязвимость программного обеспечения проверки подлинности и анализа электронных писем OpenDMARC, связанная с обходом аутентификации посредством спуфинга, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 74%
0.00806
Низкий