CVE-2021-33912
Summary
| CVE | CVE-2021-33912 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-19 18:15:00 UTC |
| Updated | 2024-01-15 17:15:00 UTC |
| Description | libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of incorrect sprintf usage in SPF_record_expand_data in spf_expand.c. The vulnerable code may be part of the supply chain of a site's e-mail infrastructure (e.g., with additional configuration, Exim can use libspf2; the Postfix web site links to unofficial patches for use of libspf2 with Postfix; older versions of spfquery relied on libspf2) but most often is not. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2021-33912 and CVE-2021-33913: Heap overflows in email validation library LibSPF2 | Nathaniel Bennett |
MISC |
nathanielbennett.com |
|
| GitHub - shevek/libspf2 at 8131fe140704eaae695e76b5cd09e39bd1dd220b |
MISC |
github.com |
|
| libspf2: Multiple vulnerabilities (GLSA 202401-22) — Gentoo security |
|
security.gentoo.org |
|
| [SECURITY] [DLA 2890-1] libspf2 security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179014 Debian Security Update for libspf2 (DLA 2890-1)
- 179776 Debian Security Update for libspf2 (CVE-2021-33912)
- 200049 Ubuntu Security Notification for Libspf2 Vulnerabilities (USN-6584-1)
- 200128 Ubuntu Security Notification for Libspf2 Vulnerabilities (USN-6584-2)
- 502222 Alpine Linux Security Update for libspf2
- 503678 Alpine Linux Security Update for libspf2
- 505886 Alpine Linux Security Update for libspf2
- 710839 Gentoo Linux libspf2 Multiple Vulnerabilities (GLSA 202401-22)