Subject: [ASA-202009-1] opendmarc: denial of service Arch Linux Security Advisory ASA-202009-1 ========================================= Severity: Medium Date : 2020-09-01 CVE-ID : CVE-2020-12460 Package : opendmarc Type : denial of service Remote : Yes Link : https://security.archlinux.org/AVG-1208 Summary ======= The package opendmarc before version 1.3.3-1 is vulnerable to denial of service. Resolution ========== Upgrade to 1.3.3-1. # pacman -Syu "opendmarc>=1.3.3-1" The problem has been fixed upstream in version 1.3.3. Workaround ========== None. Description =========== OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a specially crafted DMARC aggregate report. This can cause remote memory corruption when a '\0' byte overwrites the heap metadata of the next chunk and its PREV_INUSE flag. Impact ====== A remote attacker might be able to cause a denial of service or possibly execute arbitrary code. References ========== https://github.com/trusteddomainproject/OpenDMARC/issues/64 https://security.archlinux.org/CVE-2020-12460