CVE-2020-12460

Priority
Description
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null
termination in the function opendmarc_xml_parse that can result in a
one-byte heap overflow in opendmarc_xml when parsing a specially crafted
DMARC aggregate report. This can cause remote memory corruption when a '\0'
byte overwrites the heap metadata of the next chunk and its PREV_INUSE
flag.
Notes
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 20.04 LTS (Focal Fossa):needs-triage
Ubuntu 20.10 (Groovy Gorilla):needs-triage
More Information

Updated: 2020-09-09 23:34:54 UTC (commit 81a23a978c4436cd99e1d040e9e73e9146876281)