CVE-2019-16378

Description

OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.25

Associated Vulnerability

VulnerabilityOS Platform
opendmarc security update(DSA-4526-1) opendmarc_1.3.2-2+deb9u2_i386.debLinux
opendmarc security update(DSA-4526-1) opendmarc_1.3.2-2+deb9u2_amd64.debLinux
opendmarc security update(DSA-4526-1) opendmarc_1.3.2-6+deb10u1_amd64.debLinux
Open Source implementation of the DMARC specification (USN-4567-1) rddmarc_1.3.2-3ubuntu0.1_all.debLinux
Open Source implementation of the DMARC specification (USN-4567-1) opendmarc_1.3.2-3ubuntu0.1_i386.debLinux
Open Source implementation of the DMARC specification (USN-4567-1) opendmarc_1.3.2-3ubuntu0.1_amd64.debLinux
Open Source implementation of the DMARC specification (USN-4567-1) libopendmarc2_1.3.2-3ubuntu0.1_i386.debLinux
Open Source implementation of the DMARC specification (USN-4567-1) libopendmarc2_1.3.2-3ubuntu0.1_amd64.debLinux
Open Source implementation of the DMARC specification (USN-4567-1) rddmarc_1.3.2-3ubuntu0.1_all.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234