REDHAT-BUG-1993070: Buffer Overflow

Published Aug 12, 2021
·
Updated

Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages. CVE-2021-20314 has been assigned to this issue.

References: https://seclists.org/oss-sec/2021/q3/94 https://github.com/shevek/libspf2/commit/c37b7c13c30e225183899364b9f2efdfa85552ef

Affected Software

1 affected component
Shevek libspf2<1.2.11

Event History

Aug 12, 2021
Data Sourced
via Red Hat·10:29 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-1993070?

The severity of REDHAT-BUG-1993070 is classified as critical due to the potential for denial of service and code execution.

2

How do I fix REDHAT-BUG-1993070?

To fix REDHAT-BUG-1993070, upgrade to libspf2 version 1.2.11 or later.

3

What causes REDHAT-BUG-1993070?

REDHAT-BUG-1993070 is caused by a stack buffer overflow when processing certain SPF macros in versions of libspf2 below 1.2.11.

4

Which versions are affected by REDHAT-BUG-1993070?

Versions of libspf2 prior to 1.2.11 are affected by REDHAT-BUG-1993070.

5

Can REDHAT-BUG-1993070 lead to remote code execution?

Yes, REDHAT-BUG-1993070 can potentially lead to remote code execution through maliciously crafted SPF explanation messages.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203