SB2022011958 - Remote code execution in libspf2
Published: January 19, 2022 Updated: January 15, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Heap-based buffer overflow (CVE-ID: CVE-2021-33912)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the SPF_record_expand_data() function in spf_expand.c. A remote attacker with control over a DNS server can create a specially crafted SPF DNS record, force the library to read data from the malicious DNS server, trigger a four-byte heap-based buffer overflow and execute arbitrary code on the system.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.