|
|
Log in / Subscribe / Register

Arch Linux alert ASA-202105-13 (opendmarc)

From:  Jonas Witschel via arch-security <arch-security@lists.archlinux.org>
To:  arch-security@lists.archlinux.org
Subject:  [ASA-202105-13] opendmarc: multiple issues
Date:  Thu, 20 May 2021 20:06:15 +0200
Message-ID:  <20210520180615.fapadqjszflta4bx@archlinux.org>
Cc:  Jonas Witschel <diabonas@archlinux.org>

Arch Linux Security Advisory ASA-202105-13 ========================================== Severity: Medium Date : 2021-05-19 CVE-ID : CVE-2019-20790 CVE-2020-12272 Package : opendmarc Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-1375 Summary ======= The package opendmarc before version 1.4.1.1-1 is vulnerable to multiple issues including content spoofing and authentication bypass. Resolution ========== Upgrade to 1.4.1.1-1. # pacman -Syu "opendmarc>=1.4.1.1-1" The problems have been fixed upstream in version 1.4.1.1. Workaround ========== None. Description =========== - CVE-2019-20790 (authentication bypass) OpenDMARC before 1.4.1, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field. - CVE-2020-12272 (content spoofing) OpenDMARC before 1.4.1 allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the example.net(.example.com substring. OpenDMARC has added checking to validate that the domain element in both SPF and DKIM header fields being inspected argument contains only valid domain name characters. This has been fixed as of OpenDMARC 1.4.1 (March 2021). Impact ====== A remote attacker could spoof SPF, DMARC and DKIM authentication results. References ========== https://github.com/trusteddomainproject/OpenDMARC/blob/de... https://bugs.launchpad.net/pypolicyd-spf/+bug/1838816 https://sourceforge.net/p/opendmarc/tickets/235/ https://www.usenix.org/system/files/sec20fall_chen-jianju... https://github.com/trusteddomainproject/OpenDMARC/issues/49 https://github.com/trusteddomainproject/OpenDMARC/issues/158 https://github.com/trusteddomainproject/OpenDMARC/commit/... https://github.com/trusteddomainproject/OpenDMARC/commit/... https://github.com/trusteddomainproject/OpenDMARC/commit/... https://github.com/trusteddomainproject/OpenDMARC/blob/de... https://sourceforge.net/p/opendmarc/tickets/237/ https://github.com/trusteddomainproject/OpenDMARC/commit/... https://security.archlinux.org/CVE-2019-20790 https://security.archlinux.org/CVE-2020-12272


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds