CVE-2020-12272
Summary
| CVE | CVE-2020-12272 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-27 14:15:00 UTC |
| Updated | 2023-11-07 03:15:00 UTC |
| Description | OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the example.net(.example.com substring. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 34 Update: opendmarc-1.4.1-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: opendmarc-1.4.1-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| www.usenix.org/system/files/sec20fall_chen-jianjun_prepub_0.pdf |
MISC |
www.usenix.org |
Technical Description, Third Party Advisory |
| [SECURITY] Fedora 33 Update: opendmarc-1.4.1-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: opendmarc-1.4.1-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] [DLA 3546-1] opendmarc security update |
MLIST |
lists.debian.org |
|
| opendmarc / Tickets / #237 Security Bugs: authentication results injections attacks affecting OpenDMARC that can bypass DMARC authentication |
MISC |
sourceforge.net |
Exploit, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 281112 Fedora Security Update for opendmarc (FEDORA-2021-1ec3c5ed63)
- 281113 Fedora Security Update for opendmarc (FEDORA-2021-433e7d72ce)
- 690760 Free Berkeley Software Distribution (FreeBSD) Security Update for opendmarc - Multiple Vulnerabilities (937aa1d6-685e-11ec-a636-000c29061ce6)