PT-2026-99738 · Opendmarc · Opendmarc
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenDMARC versions prior to 1.4.3
Description
An issue exists in the Internationalized Domain Name Handler component within the
opendmarc policy query dmarc() function located in the libopendmarc/opendmarc policy.c library. A remote attacker can manipulate this function to cause an encoding error.Recommendations
Update OpenDMARC to a version newer than 1.4.2.
As a temporary mitigation, restrict the use of the
opendmarc policy query dmarc() function.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opendmarc