CVE-2008-2469: Buffer Overflow
Published Oct 23, 2008
·Updated
Heap-based buffer overflow in the SPFdnsresolvlookup function in Spfdnsresolv.c in libspf2 before 1.2.8 allows remote attackers to execute arbitrary code via a long DNS TXT record with a modified length field.
Affected Software
9 affected components
libspf libspf2=1.2.5
libspf libspf2=1.2.6
libspf libspf2=1.2.3
libspf libspf2=1.0.4
libspf libspf2<=1.2.7
libspf libspf2=1.0.2
libspf libspf2=1.2.4
libspf libspf2=1.2.1
libspf libspf2=1.0.3
Remediation
Patch Available
Event History
Oct 23, 2008
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2469?
CVE-2008-2469 is considered to be of high severity due to the potential for remote code execution.
2
How do I fix CVE-2008-2469?
To fix CVE-2008-2469, upgrade to libspf2 version 1.2.8 or later.
3
Which versions of libspf2 are affected by CVE-2008-2469?
Versions of libspf2 prior to 1.2.8, including 1.0.2, 1.0.4, 1.2.1 to 1.2.7, and others, are affected by CVE-2008-2469.
4
What type of vulnerability is CVE-2008-2469?
CVE-2008-2469 is a heap-based buffer overflow vulnerability.
5
Can CVE-2008-2469 allow attackers to execute arbitrary code?
Yes, CVE-2008-2469 can allow remote attackers to execute arbitrary code through crafted DNS TXT records.