CVE-2020-12460
Summary
| CVE | CVE-2020-12460 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-27 23:15:00 UTC |
| Updated | 2023-11-07 03:15:00 UTC |
| Description | OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a specially crafted DMARC aggregate report. This can cause remote memory corruption when a '\0' byte overwrites the heap metadata of the next chunk and its PREV_INUSE flag. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 34 Update: opendmarc-1.4.0-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Memory corruption in opendmarc_xml() · Issue #64 · trusteddomainproject/OpenDMARC · GitHub |
MISC |
github.com |
Exploit, Third Party Advisory |
| [SECURITY] Fedora 34 Update: opendmarc-1.4.1-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: opendmarc-1.4.1-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: opendmarc-1.4.1-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: opendmarc-1.4.1-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| opendmarc | Free Communications software downloads at SourceForge.net |
MISC |
sourceforge.net |
Product, Third Party Advisory |
| [SECURITY] Fedora 34 Update: opendmarc-1.4.0-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] [DLA 2639-1] opendmarc security update |
MLIST |
lists.debian.org |
|
| OpenDMARC: Heap-based buffer overflow (GLSA 202011-02) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178648 Debian Security Update for opendmarc (DLA 2639-1)
- 281112 Fedora Security Update for opendmarc (FEDORA-2021-1ec3c5ed63)
- 281113 Fedora Security Update for opendmarc (FEDORA-2021-433e7d72ce)
- 281233 Fedora Security Update for opendmarc (FEDORA-2021-c1b846164e)
- 690760 Free Berkeley Software Distribution (FreeBSD) Security Update for opendmarc - Multiple Vulnerabilities (937aa1d6-685e-11ec-a636-000c29061ce6)