--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2021-889af802f2
2021-07-20 01:05:46.430982
--------------------------------------------------------------------------------
Name : opendmarc
Product : Fedora 34
Version : 1.4.1.1
Release : 3.fc34
URL :
http://www.trusteddomain.org/opendmarc.html
Summary : A Domain-based Message Authentication, Reporting & Conformance (DMARC)
milter and library
Description :
OpenDMARC (Domain-based Message Authentication, Reporting & Conformance)
provides an open source library that implements the DMARC verification
service plus a milter-based filter application that can plug in to any
milter-aware MTA, including sendmail, Postfix, or any other MTA that supports
the milter protocol.
The DMARC sender authentication system is still a draft standard, working
towards RFC status.
The database schema required for some functions is provided in
/usr/share/opendmarc/db. The rddmarc tools are provided in
/usr/share/opendmarc/contrib/rddmarc.
--------------------------------------------------------------------------------
Update Information:
Fix for CVE-2021-34555 as well as fix for using /var in service file warning.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Jul 11 2021 Kevin Fenzi <kevin(a)scrye.com> - 1.4.1.1-3
- Fix use of /var/run in service file. Fixes rhbz#1915468
* Sun Jul 11 2021 Kevin Fenzi <kevin(a)scrye.com> - 1.4.1.1-2
- Add patch for CVE-2021-34555. Fixes rhbz#1974707
* Sat Jun 19 2021 Kevin Fenzi <kevin(a)scrye.com> - 1.4.1.1-1
- Update to 1.4.1.1. Fixes rhbz#1972292
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1915468 - /usr/lib/systemd/system/opendmarc.service:8: PIDFile= references a
path below legacy directory /var/run/, updating /var/run/opendmarc/opendmarc.pid ���
/run/opendmarc/opendmarc.pid; please update the unit file accordingly.
https://bugzilla.redhat.com/show_bug.cgi?id=1915468
[ 2 ] Bug #1974710 - CVE-2021-34555 opendmarc: remote NULL pointer dereference may lead
to a DoS [fedora-34]
https://bugzilla.redhat.com/show_bug.cgi?id=1974710
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2021-889af802f2' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------