Vulnerability Description
An issue was discovered in OpenDKIM through 2.10.3, and 2.11.x through 2.11.0-Beta2. It fails to keep track of ordinal numbers when removing fake Authentication-Results header fields, which allows a remote attacker to craft an e-mail message with a fake sender address such that programs that rely on Authentication-Results from OpenDKIM will treat the message as having a valid DKIM signature when in fact it has none.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opendkim | Opendkim | <= 2.10.3 |
References
- https://github.com/trusteddomainproject/OpenDKIM/issues/148Issue Tracking
- https://lists.debian.org/debian-lts-announce/2023/12/msg00002.html
- https://github.com/trusteddomainproject/OpenDKIM/issues/148Issue Tracking
- https://lists.debian.org/debian-lts-announce/2023/12/msg00002.html
FAQ
What is CVE-2022-48521?
CVE-2022-48521 is a vulnerability with a CVSS score of 5.3 (MEDIUM). An issue was discovered in OpenDKIM through 2.10.3, and 2.11.x through 2.11.0-Beta2. It fails to keep track of ordinal numbers when removing fake Authentication-Results header fields, which allows a r...
How severe is CVE-2022-48521?
CVE-2022-48521 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-48521?
Check the references section above for vendor advisories and patch information. Affected products include: Opendkim Opendkim.