CVE-2019-16378
Published: 17 September 2019
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message.
Priority
Severity score breakdown
Parameter | Value |
---|---|
Base score | 9.8 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16378
- https://github.com/trusteddomainproject/OpenDMARC/pull/48
- http://www.openwall.com/lists/oss-security/2019/09/17/2
- https://bugs.debian.org/940081
- https://www.openwall.com/lists/oss-security/2019/09/11/8
- https://ubuntu.com/security/notices/USN-4567-1
- NVD
- Launchpad
- Debian