#1033805 opendmarc: Segmentation fault with 3072-bit key signatures in ARC-Seal headers

Package:
opendmarc
Source:
opendmarc
Description:
Domain-based Message Authentication, Reporting and Conformance (DMARC) milter
Submitter:
Scott Kitterman
Date:
2023-04-13 05:15:03 UTC
Severity:
normal
Tags:
#1033805#5
Date:
2023-04-01 19:59:56 UTC
From:
To:
Currently opendmarc in Stable, Testing, and Unstable will crash if they
key used in an ARC header field is 3072 bit RSA or longer.  This really
needs to be fixed prior to release since, in normal usage, when a milter
crashes it stops all mail flow on the system.  Since the key size is an
attribute decided by the sending domain, there's no work around on the
receiver side to avoid the specific keys at issue.

Longer RSA keys are becoming more common and this trend will continue
through Bookworm's life, so the impact will only grow.

Patch available in the upstream GitHub repository:

https://github.com/trusteddomainproject/OpenDMARC/issues/183

Scott K

#1033805#12
Date:
2023-04-02 06:34:41 UTC
From:
To:
See the report at #1007926, and the proposed stable update in #1033591.

Debian testing/1.4.2-2 is not affected as far as I have seen – do you
use 1.4.2-2 and it crashes for you?

#1033805#15
Date:
2023-04-02 07:43:15 UTC
From:
To:
Also note that we have been shipping the linked patch in Debian’s
opendmarc for a while now. It is included in stable, testing, unstable
as ‘arcseal-segfaults.patch’.

#1033805#20
Date:
2023-04-02 14:02:14 UTC
From:
To:
I'm not running it myself.  I thought people on postfix-users reported the problem with our package.  If you're confident it's already addressed, please close the bug and sorry for the noise.

Scott K

#1033805#25
Date:
2023-04-13 05:05:43 UTC
From:
To:
We’ve seen no evidence of crashing in 1.4.2-1 or 1.4.2-2, closing.