Trusteddomain OpenDMARC 1.2.0 Beta 0

CPE Details

Trusteddomain OpenDMARC 1.2.0 Beta 0
1.2.0
2019-09-17
14h17 +00:00
2019-09-17
14h17 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:trusteddomain:opendmarc:1.2.0:beta0:*:*:*:*:*:*

Informations

Vendor

trusteddomain

Product

opendmarc

Version

1.2.0

Update

beta0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-12460 2020-07-27 20h52 +00:00 OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a specially crafted DMARC aggregate report. This can cause remote memory corruption when a '\0' byte overwrites the heap metadata of the next chunk and its PREV_INUSE flag.
9.8
Critical
CVE-2020-12272 2020-04-26 22h00 +00:00 OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the example.net(.example.com substring.
5.3
Medium
CVE-2019-16378 2019-09-17 09h24 +00:00 OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message.
9.8
Critical