CVE Vulnerabilities

CVE-2021-34555

NULL Pointer Dereference

Published: Jun 10, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

OpenDMARC 1.4.1 and 1.4.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a multi-value From header field.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Opendmarc Trusteddomain 1.4.1 (including) 1.4.1 (including)
Opendmarc Trusteddomain 1.4.1.1 (including) 1.4.1.1 (including)
Opendmarc Ubuntu bionic *
Opendmarc Ubuntu groovy *
Opendmarc Ubuntu hirsute *
Opendmarc Ubuntu impish *
Opendmarc Ubuntu kinetic *
Opendmarc Ubuntu trusty *
Opendmarc Ubuntu xenial *

Potential Mitigations

References