OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message.
| Software | From | Fixed in |
|---|---|---|
| trusteddomain / opendmarc | 1.4.0-beta1 | 1.4.0-beta1.x |
| trusteddomain / opendmarc | 1.4.0-beta | 1.4.0-beta.x |
| trusteddomain / opendmarc | - | 1.3.2.x |
| debian / debian_linux | 9.0 | 9.0.x |
| debian / debian_linux | 10.0 | 10.0.x |
| fedoraproject / fedora | 29 | 29.x |
| fedoraproject / fedora | 30 | 30.x |
| fedoraproject / fedora | 31 | 31.x |
| canonical / ubuntu_linux | 18.04 | 18.04.x |