Impact
The OpenDKIM library, a component of the Trusted Domain Project, contains an off‑by‑one error in the dkim_qp_decode function of util.c. A malicious actor can craft a DKIM query that causes the decoder to read or write outside the bounds of its buffer. This memory corruption could lead to application instability, denial of service, or, in the worst case, arbitrary code execution if the underlying platform is vulnerable to buffer overflow exploitation.
Affected Systems
The vulnerability affects Trusted Domain Project’s OpenDKIM version 2.11.0 and earlier. Any system running one of these releases and processing DKIM messages is at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. No EPSS score is reported, and the issue is not listed in the CISA KEV catalog. The exploit is publicly available and can be performed remotely, and the vendor has not issued a response, which increases the likelihood that active exploitation may occur. Organizations should consider these factors when prioritizing remediation.
OpenCVE Enrichment