在 Trusted Domain Project 的 OpenDMARC 1.4.2 及更早版本中检测到一处漏洞。受该漏洞影响的是 DMARC 记录解析器组件中 libopendmarc/opendmarc_util.c 文件里的 opendmarc_util_cleanup 函数。对该函数的不当操作会导致缓冲区溢出/下溢(off-by-one 错误)。攻击者可远程发起攻击。目前相关利用代码已公开,可能被恶意利用。修复该漏洞的补丁为 b3b1da9264bc80324094a27c71e7369bdedc62ae。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Trusted Domain Project | OpenDMARC | 1.4.0 |
cpe:2.3:a:trusted_domain_project:opendmarc:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101015 | 7.3 HIGH | Trusted Domain Project OpenDMARC policy.c improper validation of unsafe equivalence in inp |
| CVE-2026-100891 | 7.3 HIGH | Trusted Domain Project OpenDMARC Internationalized Domain Name opendmarc_policy.c opendmar |
| CVE-2026-101016 | 6.5 MEDIUM | Trusted Domain Project OpenDMARC opendmarc_policy.c opendmarc_policy_parse_dmarc exception |
| CVE-2026-101017 | 6.5 MEDIUM | Trusted Domain Project OpenDMARC opendmarc_policy.c strcasecmp exceptional condition |
| CVE-2026-100895 | 5.3 MEDIUM | Trusted Domain Project OpenARC libopenarc arc-canon.c arc_parse_canon_t null pointer deref |
| CVE-2026-100890 | 5.3 MEDIUM | Trusted Domain Project OpenDMARC SPF Parser opendmarc_spf.c opendmarc_spf_ipv6_explode nul |
No comments yet