天下漏洞,尽知其名
MEDIUM

CVE-2026-101017 OpenDMARC 异常条件处理漏洞

影响远程攻击者可触发异常条件导致服务异常

AI 研判

OpenDMARC 1.4.2 及之前版本中,libopendmarc/opendmarc_policy.c 的 strcasecmp 函数调用存在异常条件处理缺陷。该漏洞可被远程利用,且利用代码已公开。厂商已被告知但未作回应。

影响范围

OpenDMARC

Trusted Domain Project OpenDMARC 至 1.4.2 版本(含)受影响,更高版本是否修复暂无公开信息。

漏洞详情

漏洞类型为异常条件处理不当(CWE-703 类)。程序在调用 strcasecmp 进行字符串比较时未妥善处理异常输入,攻击者可通过构造特定数据触发异常。由于该函数位于 DMARC 策略处理库中,远程发送特制邮件或构造相关请求即可触发。

利用条件与风险

利用无需认证,可远程发起,且公开利用代码已存在,实战风险较高;但 CVSS 6.5 表明主要影响可用性,暂未见代码执行或权限提升证据。

修复建议

官方暂未发布修复版本,建议关注 Trusted Domain Project 后续更新;临时可对 OpenDMARC 输入进行过滤或限制访问来源以降低风险。

原始情报

A vulnerability was found in Trusted Domain Project OpenDMARC up to 1.4.2. This vulnerability affects the function strcasecmp in the library libopendmarc/opendmarc_policy.c. The manipulation results in handling of exceptional conditions. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.