漏洞信息详情
OpenDMARC 安全漏洞
漏洞简介
OpenDMARC是一款DMARC(基于域的消息认证、报告和一致性)规范的开源实现。
OpenDMARC 1.3.2及之前版本和1.4.x版本至1.4.0-Beta1版本中存在安全漏洞。攻击者可利用该漏洞绕过签名检查。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/trusteddomainproject/OpenDMARC/pull/48
参考网址
来源:DEBIAN
链接:https://www.debian.org/security/2019/dsa-4526
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2019/09/17/2
来源:MISC
链接:https://www.openwall.com/lists/oss-security/2019/09/11/8
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/PEUBIHJLMPMB6KHOSGDMUQKSAW4HOCYM/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/Y7RT6ID7MBCEPNZEIUKK2TZIOCYPJR6E/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/6HEWDFGRKQHIWKFZH5BNWQDGUPNR7VH3/
来源:BUGTRAQ
链接:https://seclists.org/bugtraq/2019/Sep/36
来源:MISC
链接:https://bugs.debian.org/940081
来源:MISC
链接:https://github.com/trusteddomainproject/OpenDMARC/pull/48
来源:UBUNTU
链接:https://usn.ubuntu.com/4567-1/
来源:www.debian.org
链接:https://www.debian.org/security/2019/dsa-4526
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3439/
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/OpenDMARC-adress-spoofing-via-From-field-duplication-30369
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159489/Ubuntu-Security-Notice-USN-4567-1.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/154544/Debian-Security-Advisory-4526-1.html
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-16378
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.3552/
受影响实体
暂无
补丁
- OpenDMARC 安全漏洞的修复措施<!--2019-9-17-->
还没有评论,来说两句吧...