PT-2026-99806 · Opendmarc · Opendmarc
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenDMARC versions prior to 1.4.3
Description
A remote attack can be initiated against the DMARC Record Parser component. The issue resides in the
opendmarc util cleanup() function within the libopendmarc/opendmarc util.c library, where a manipulation leads to an off-by-one error. An off-by-one is a specific type of error where an iterative loop or memory allocation is off by a single unit, potentially leading to memory corruption.Recommendations
Deploy patch b3b1da9264bc80324094a27c71e7369bdedc62ae for versions prior to 1.4.3.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opendmarc