CVE-2020-12460: Debian Linux
Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a specially crafted DMARC aggregate report. This can cause remote memory corruption when a '\0' byte overwrites the heap metadata of the next chunk and its PREV_INUSE flag.
Affected products
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 33 only; version 34 only
- Trusteddomain Opendmarc: up to and including 1.3.2; version 1.4.0 only
Published 2020-07-27. Last modified 2026-06-17.