CVE-2019-20790
Summary
| CVE | CVE-2019-20790 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-27 14:15:00 UTC |
| Updated | 2023-11-07 03:09:00 UTC |
| Description | OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 34 Update: opendmarc-1.4.1-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: opendmarc-1.4.1-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| www.usenix.org/system/files/sec20fall_chen-jianjun_prepub_0.pdf |
MISC |
www.usenix.org |
Technical Description, Third Party Advisory |
| [SECURITY] Fedora 33 Update: opendmarc-1.4.1-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| opendmarc / Tickets / #235 Security Bug: OpenDMARC can can be bypassed when it's used with pypolicyd-spf |
MISC |
sourceforge.net |
Exploit, Third Party Advisory |
| [SECURITY] Fedora 33 Update: opendmarc-1.4.1-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Bug #1838816 “pypolicyd-spf returns false result, which may be ...” : Bugs : pypolicyd-spf |
MISC |
bugs.launchpad.net |
Exploit, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 281112 Fedora Security Update for opendmarc (FEDORA-2021-1ec3c5ed63)
- 281113 Fedora Security Update for opendmarc (FEDORA-2021-433e7d72ce)
- 690760 Free Berkeley Software Distribution (FreeBSD) Security Update for opendmarc - Multiple Vulnerabilities (937aa1d6-685e-11ec-a636-000c29061ce6)