Heap-based buffer overflow in libspf2 - CVE-2021-33912
Published: January 15, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the SPF_record_expand_data() function in spf_expand.c. A remote attacker with control over a DNS server can create a specially crafted SPF DNS record, force the library to read data from the malicious DNS server, trigger a four-byte heap-based buffer overflow and execute arbitrary code on the system.
Affected software
Gentoo Linux
Ubuntu
libmail-spf-xs-perl (Ubuntu package)
libspf2-2 (Ubuntu package)
libspf2-dev (Ubuntu package)
spfquery (Ubuntu package)
mail-filter/libspf2
How to mitigate CVE-2021-33912
libspf2-2 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.2.10-7+deb9u2build0.20.04.1
libspf2-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 1.2.10-7+deb9u2build0.20.04.1
spfquery (Ubuntu package) - addressed in versions Ubuntu Pro, 1.2.10-7+deb9u2build0.20.04.1
mail-filter/libspf2 - update to 1.2.11