Impact
A defect exists in the opendmarc_policy_query_dmarc function of OpenDMARC’s Internationalized Domain Name handler, allowing an attacker to manipulate input encoding and trigger an error. The exploitation can be carried out from a remote source and is publicly disclosed, indicating that execution is feasible. The failure to process IDN correctly may lead to further weaknesses in the system, potentially exposing sensitive configuration or allowing denial of service, though definitive data on escalation is not provided in the description.
Affected Systems
Trusted Domain Project’s OpenDMARC library versions up to and including 1.4.2 are impacted. Systems running these versions with IDN handling enabled are vulnerable.
Risk and Exploitability
The CVSS score of 6.9 places this flaw in the medium severity range, suggesting that while it may not provide full remote code execution, it does create a pathway for disruptive attacks. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, implying that large‑scale exploitation is not actively reported yet. However, the attack is described as possible to launch remotely, and the public disclosure of the exploit indicates that attackers could attempt to use this vector. Organizations should evaluate the attack surface and consider the potential impact of an IDN parsing error in their mail flow infrastructure.
OpenCVE Enrichment