CVE-2019-16378Authentication Bypass by Spoofing in Opendmarc

Severity
9.8CRITICALNVD
EPSS
1.3%
top 20.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 17
Latest updateMay 24

Description

OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

Debiantrusteddomain/opendmarc< 1.3.2-7+3
debiandebian/opendmarc< opendmarc 1.3.2-7 (bookworm)

Also affects: Debian Linux 10.0, 9.0, Fedora 29, 30, 31, Ubuntu Linux 18.04

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x9f6-xw7x-fm76: OpenDMARC through 12022-05-24
OSV
CVE-2019-16378: OpenDMARC through 12019-09-17

📋Vendor Advisories

2
Ubuntu
OpenDMARC vulnerability2020-10-05
Debian
CVE-2019-16378: opendmarc - OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-by...2019

💬Community

3
Bugzilla
CVE-2019-16378 opendmarc: Signature-bypass vulnerability with multiple 'From' addresses [epel-all]2019-09-18
Bugzilla
CVE-2019-16378 opendmarc: Signature-bypass vulnerability with multiple 'From' addresses [fedora-all]2019-09-18
Bugzilla
CVE-2019-16378 opendmarc: Signature-bypass vulnerability with multiple 'From' addresses2019-09-18
CVE-2019-16378 — Authentication Bypass by Spoofing | cvebase