First published: Mon Apr 27 2020(Updated: )
OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the example.net(.example.com substring.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/opendmarc | <1.3.1+dfsg-3ubuntu0.1~ | 1.3.1+dfsg-3ubuntu0.1~ |
ubuntu/opendmarc | <1.3.2-7ubuntu0.1 | 1.3.2-7ubuntu0.1 |
ubuntu/opendmarc | <1.3.2-3ubuntu0.2 | 1.3.2-3ubuntu0.2 |
ubuntu/opendmarc | <1.4.2 | 1.4.2 |
Trusteddomain Opendmarc | >=1.0.0<=1.3.2 | |
Trusteddomain Opendmarc | =1.4.0 | |
Trusteddomain Opendmarc | =1.4.0-beta0 | |
Trusteddomain Opendmarc | =1.4.0-beta1 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
>=1.0.0<=1.3.2 | ||
=1.4.0 | ||
=1.4.0-beta0 | ||
=1.4.0-beta1 | ||
=33 | ||
=34 | ||
debian/opendmarc | <=1.3.2-6+deb10u2 | 1.3.2-6+deb10u4 1.4.0~beta1+dfsg-6+deb11u1 1.4.2-2 1.4.2-4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12272 is a vulnerability in OpenDMARC through 1.3.2 and 1.4.x that allows attackers to inject authentication results and provide false information about the domain that originated an email message.
CVE-2020-12272 has a severity level of medium, with a CVSS score of 5.3.
CVE-2020-12272 affects OpenDMARC versions 1.0.0 through 1.3.2 and 1.4.x, allowing for the incorrect parsing and interpretation of SPF/DKIM authentication results.
To fix the CVE-2020-12272 vulnerability in OpenDMARC, make sure to update to version 1.3.2-6+deb10u4, 1.4.0~beta1+dfsg-6+deb11u1, 1.4.2-2, or 1.4.2-3.
For more information about the CVE-2020-12272 vulnerability, you can refer to the following references: [Reference 1](https://lists.debian.org/debian-lts-announce/2023/08/msg00035.html) and [Reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2D4JGHMALEJEWWG56DKR5OZB22TK7W5B/).