An issue was discovered in OpenDKIM through 2.10.3, and 2.11.x through 2.11.0-Beta2. It fails to keep track of ordinal numbers when removing fake Authentication-Results header fields, which allows a remote attacker to craft an e-mail message with a fake sender address such that programs that rely on Authentication-Results from OpenDKIM will treat the message as having a valid DKIM signature when in fact it has none.
{
"binaries": [
{
"binary_version": "2.10.3-3build1",
"binary_name": "libopendkim-dev"
},
{
"binary_version": "2.10.3-3build1",
"binary_name": "libopendkim10"
},
{
"binary_version": "2.10.3-3build1",
"binary_name": "librbl-dev"
},
{
"binary_version": "2.10.3-3build1",
"binary_name": "librbl1"
},
{
"binary_version": "2.10.3-3build1",
"binary_name": "libvbr-dev"
},
{
"binary_version": "2.10.3-3build1",
"binary_name": "libvbr2"
},
{
"binary_version": "2.10.3-3build1",
"binary_name": "opendkim"
},
{
"binary_version": "2.10.3-3build1",
"binary_name": "opendkim-tools"
}
]
}{
"binaries": [
{
"binary_version": "2.11.0~alpha-11build1",
"binary_name": "libopendkim-dev"
},
{
"binary_version": "2.11.0~alpha-11build1",
"binary_name": "libopendkim11"
},
{
"binary_version": "2.11.0~alpha-11build1",
"binary_name": "librbl-dev"
},
{
"binary_version": "2.11.0~alpha-11build1",
"binary_name": "librbl1"
},
{
"binary_version": "2.11.0~alpha-11build1",
"binary_name": "libvbr-dev"
},
{
"binary_version": "2.11.0~alpha-11build1",
"binary_name": "libvbr2"
},
{
"binary_version": "2.11.0~alpha-11build1",
"binary_name": "opendkim"
},
{
"binary_version": "2.11.0~alpha-11build1",
"binary_name": "opendkim-tools"
}
]
}{
"binaries": [
{
"binary_version": "2.11.0~beta2-1",
"binary_name": "libopendkim-dev"
},
{
"binary_version": "2.11.0~beta2-1",
"binary_name": "libopendkim11"
},
{
"binary_version": "2.11.0~beta2-1",
"binary_name": "librbl-dev"
},
{
"binary_version": "2.11.0~beta2-1",
"binary_name": "librbl1"
},
{
"binary_version": "2.11.0~beta2-1",
"binary_name": "libvbr-dev"
},
{
"binary_version": "2.11.0~beta2-1",
"binary_name": "libvbr2"
},
{
"binary_version": "2.11.0~beta2-1",
"binary_name": "opendkim"
},
{
"binary_version": "2.11.0~beta2-1",
"binary_name": "opendkim-tools"
}
]
}{
"binaries": [
{
"binary_version": "2.11.0~beta2-6",
"binary_name": "libopendkim-dev"
},
{
"binary_version": "2.11.0~beta2-6",
"binary_name": "libopendkim11"
},
{
"binary_version": "2.11.0~beta2-6",
"binary_name": "librbl-dev"
},
{
"binary_version": "2.11.0~beta2-6",
"binary_name": "librbl1"
},
{
"binary_version": "2.11.0~beta2-6",
"binary_name": "libvbr-dev"
},
{
"binary_version": "2.11.0~beta2-6",
"binary_name": "libvbr2"
},
{
"binary_version": "2.11.0~beta2-6",
"binary_name": "miltertest"
},
{
"binary_version": "2.11.0~beta2-6",
"binary_name": "opendkim"
},
{
"binary_version": "2.11.0~beta2-6",
"binary_name": "opendkim-tools"
}
]
}{
"binaries": [
{
"binary_version": "2.11.0~beta2-9build4",
"binary_name": "libopendkim-dev"
},
{
"binary_version": "2.11.0~beta2-9build4",
"binary_name": "libopendkim11"
},
{
"binary_version": "2.11.0~beta2-9build4",
"binary_name": "librbl-dev"
},
{
"binary_version": "2.11.0~beta2-9build4",
"binary_name": "librbl1"
},
{
"binary_version": "2.11.0~beta2-9build4",
"binary_name": "libvbr-dev"
},
{
"binary_version": "2.11.0~beta2-9build4",
"binary_name": "libvbr2"
},
{
"binary_version": "2.11.0~beta2-9build4",
"binary_name": "miltertest"
},
{
"binary_version": "2.11.0~beta2-9build4",
"binary_name": "opendkim"
},
{
"binary_version": "2.11.0~beta2-9build4",
"binary_name": "opendkim-tools"
}
]
}{
"binaries": [
{
"binary_version": "2.11.0~beta2-9.2",
"binary_name": "libopendkim-dev"
},
{
"binary_version": "2.11.0~beta2-9.2",
"binary_name": "libopendkim11"
},
{
"binary_version": "2.11.0~beta2-9.2",
"binary_name": "librbl-dev"
},
{
"binary_version": "2.11.0~beta2-9.2",
"binary_name": "librbl1"
},
{
"binary_version": "2.11.0~beta2-9.2",
"binary_name": "libvbr-dev"
},
{
"binary_version": "2.11.0~beta2-9.2",
"binary_name": "libvbr2"
},
{
"binary_version": "2.11.0~beta2-9.2",
"binary_name": "miltertest"
},
{
"binary_version": "2.11.0~beta2-9.2",
"binary_name": "opendkim"
},
{
"binary_version": "2.11.0~beta2-9.2",
"binary_name": "opendkim-tools"
}
]
}