dkim-milter does not properly handle verification of messages signed with a key that has been revoked in DNS (the p= flag set to an empty string). References: http://www.openwall.com/lists/oss-security/2009/03/01/1 http://sourceforge.net/tracker/index.php?func=detail&aid=2508602&group_id=139420&atid=744358 http://www.debian.org/security/2009/dsa-1728 A CVE has been requested, but not assigned yet. This has been fixed upstream in 2.8.1, which is shipped in F10, but F9 has 2.5.1 which would be vulnerable to this issue.
Created dkim-milter tracking bugs for this issue Affects: F9 [bug #488595]
Created attachment 334070 [details] Upstream patch to fix the issue
dkim-milter-2.8.1-1.fc9 has been submitted as an update for Fedora 9. http://admin.fedoraproject.org/updates/dkim-milter-2.8.1-1.fc9
dkim-milter-2.8.1-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.