CVE-2026-101014 HIGH
← Quay lại danh sách
Dịch vụ / phần mềm liên quan:
Chưa phân loại — không khớp danh sách dịch vụ/phần mềm đang theo dõi (xem/thêm ở
internal/cve/categories.go), hoặc NVD chưa cung cấp đủ dữ liệu vendor/sản phẩm cho CVE này.
Mô tả
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely. The exploit is now public and may be used. The patch is named b3b1da9264bc80324094a27c71e7369bdedc62ae. To fix this issue, it is recommended to deploy a patch.
Chi tiết
| Trạng thái | Received |
| Điểm CVSS | 7.3 (v3.1) |
| Vector CVSS | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
| Ngày công bố | 16:17 28/09/2026 |
| Ngày cập nhật | 16:17 28/09/2026 |
| Nguồn dữ liệu | nvd |
CWE
Sản phẩm bị ảnh hưởng
Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.
Tài liệu tham khảo
- [cna@vuldb.com] https://github.com/trusteddomainproject/OpenDMARC/commit/b3b1da9264bc80324094a27c71e7369bdedc62ae
- [cna@vuldb.com] https://github.com/trusteddomainproject/OpenDMARC/pull/188
- [cna@vuldb.com] https://github.com/trusteddomainproject/OpenDMARC/pull/344
- [cna@vuldb.com] https://vuldb.com/cve/CVE-2026-101014
- [cna@vuldb.com] https://vuldb.com/submit/917100
- [cna@vuldb.com] https://vuldb.com/vuln/410884
- [cna@vuldb.com] https://vuldb.com/vuln/410884/cti
- [cna@vuldb.com] https://weitongli.com/share/opendmarc-cleanup-off-by-one.html
Lịch sử thay đổi
| Thời gian | Loại | Trường | Giá trị cũ | Giá trị mới |
|---|---|---|---|---|
| 16:17 28/09/2026 | CREATED | cve | HIGH |