在 Truedsted Domain Project OpenDMARC(版本 1.4.2 及之前)中发现了一个安全漏洞。该漏洞影响了 DMARC 解析器组件中 libopendmarc/opendmarc_policy.c 文件中的某个未知函数。对参数 pct 的操作会导致整数溢出。远程攻击者可以利用此漏洞进行攻击。该利用代码已被公开披露,可能被恶意使用。厂商已提前被联系,但对此漏洞披露未作任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Trusted Domain Project | OpenDMARC | 1.4.0 |
cpe:2.3:a:trusted_domain_project:opendmarc:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101281 | 7.3 HIGH | Trusted Domain Project OpenDMARC SPF Macro opendmarc_spf.c opendmarc_sp2_find_mailfrom_dom |
| CVE-2026-101280 | 7.3 HIGH | Trusted Domain Project OpenDMARC Multi-Record Set opendmarc_policy_query_dmarc authenticat |
| CVE-2026-101278 | 4.3 MEDIUM | Trusted Domain Project OpenDMARC PSL Wildcard opendmarc_tld.c : opendmarc_get_tld origin v |
No comments yet