USN-6356-1: OpenDMARC vulnerabilities
Jianjun Chen, Vern Paxson and Jian Jiang discovered that OpenDMARC incorrectly handled certain inputs. If a user or an automated system were tricked into receiving crafted inputs, an attacker could possibly use this to falsify the domain of an e-mails origin. (CVE-2020-12272) Patrik Lantz discovered that OpenDMARC incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2020-12460)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6356-1?
The severity of USN-6356-1 is medium.
How does OpenDMARC handle inputs in USN-6356-1?
OpenDMARC incorrectly handles certain inputs in USN-6356-1.
What is the impact of the vulnerability in USN-6356-1?
If a user or an automated system receives crafted inputs, an attacker could falsify the domain of an email's origin.
Which software versions are affected by USN-6356-1?
The software versions affected by USN-6356-1 are libopendmarc2 1.3.2-7ubuntu0.1, opendmarc 1.3.2-7ubuntu0.1, libopendmarc2 1.3.2-3ubuntu0.2, opendmarc 1.3.2-3ubuntu0.2, libopendmarc2 1.3.1+dfsg-3ubuntu0.1~esm1, and opendmarc 1.3.1+dfsg-3ubuntu0.1~esm1.
How can I fix the vulnerability in USN-6356-1?
To fix the vulnerability in USN-6356-1, update the libopendmarc2 and opendmarc packages to the specified versions.