CVE-2021-33912: Buffer Overflow
Last updated 24 July 2024
Other sources
libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of incorrect sprintf usage in SPFrecordexpanddata in spfexpand.c. The vulnerable code may be part of the supply chain of a site's e-mail infrastructure (e.g., with additional configuration, Exim can use libspf2; the Postfix web site links to unofficial patches for use of libspf2 with Postfix; older versions of spfquery relied on libspf2) but most often is not.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-33912?
CVE-2021-33912 is a vulnerability in libspf2 before 1.2.11 that allows remote attackers to execute arbitrary code with a crafted SPF DNS record.
How severe is CVE-2021-33912?
CVE-2021-33912 has a severity rating of 9.8 (critical).
Which software versions are affected by CVE-2021-33912?
Versions of libspf2 before 1.2.11 and Debian Linux 9.0 are affected by CVE-2021-33912.
How can the vulnerability be fixed?
To fix CVE-2021-33912, upgrade to libspf2 version 1.2.11 or apply the necessary security patches.
Is there any additional information about CVE-2021-33912?
Yes, you can find more information about CVE-2021-33912 in the provided references.