Log

ASA-202105-14 edited at 19 May 2021 11:20:34
Impact
+ A privileged remote attacker could cause the MariaDB to hang or crash.
ASA-202105-14 created at 19 May 2021 11:20:04
ASA-202105-13 edited at 19 May 2021 11:18:28
Impact
+ A remote attacker could spoof SPF, DMARC and DKIM authentication results.
ASA-202105-13 created at 19 May 2021 11:17:38
CVE-2020-12272 edited at 19 May 2021 11:16:39
Description
- OpenDMARC through 1.3.2 and 1.4.x before 1.4.1 allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the example.net(.example.com substring.
+ OpenDMARC before 1.4.1 allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the example.net(.example.com substring.
OpenDMARC has added checking to validate that the domain element in both SPF and DKIM header fields being inspected argument contains only valid domain name characters. This has been fixed as of OpenDMARC 1.4.1 (March 2021).
CVE-2019-20790 edited at 19 May 2021 11:16:30
Description
- OpenDMARC through 1.3.2 and 1.4.x before 1.4.1, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.
+ OpenDMARC before 1.4.1, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.
ASA-202105-12 edited at 19 May 2021 11:15:31
Impact
+ An attacker could emit arbitrary X protocol requests to the X server through crafted string parameters.
ASA-202105-12 created at 19 May 2021 11:13:31
ASA-202105-11 edited at 19 May 2021 11:13:00
Impact
+ A remote attacker could cause excessive use of the server's bandwidth and resources, leading to denial of service, impersonate other servers, or leak secret strings through timing attacks.
ASA-202105-11 created at 19 May 2021 11:10:07