Bug#1041107: opendkim: CVE-2022-48521

2023-07-19 Thread Björn Persson
Package: opendkim Version: 2.11.0~beta2-8 Followup-For: Bug #1041107 To expand on the brief CVE description: When OpenDKIM removes fake Authentication-Results fields (as required in https://www.rfc-editor.org/rfc/rfc8601#section-5), it doesn't account for the fact that – at least in Postfix – thi

Bug#1041107: opendkim: CVE-2022-48521

2023-07-14 Thread Moritz Mühlenhoff
Source: opendkim X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for opendkim. CVE-2022-48521[0]: | An issue was discovered in OpenDKIM through 2.10.3, and 2.11.x | through 2.11.0-Beta2. It fails to keep track of ordinal num