CVE-2022-48521
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Jul 11, 2023
Updated: Dec 3, 2023
Summary
CVE-2022-48521 is a vulnerability affecting OpenDKIM versions 2.10.3 and 2.11.x through 2.11.0-Beta2. The issue arises due to a tracking problem with ordinal numbers in OpenDKIM's handling of Authentication-Results header fields. Maliciously crafted e-mail messages can exploit this vulnerability by including fake sender addresses with forged Authentication-Results headers. Subsequently, software relying on OpenDKIM for signature validation may incorrectly assume that the message possesses a valid DKIM signature, despite it being nonexistent.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- OpenDKIM OpenDKIM