REDHAT-BUG-1993070: Buffer Overflow
Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages. CVE-2021-20314 has been assigned to this issue.
References: https://seclists.org/oss-sec/2021/q3/94 https://github.com/shevek/libspf2/commit/c37b7c13c30e225183899364b9f2efdfa85552ef
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1993070?
The severity of REDHAT-BUG-1993070 is classified as critical due to the potential for denial of service and code execution.
How do I fix REDHAT-BUG-1993070?
To fix REDHAT-BUG-1993070, upgrade to libspf2 version 1.2.11 or later.
What causes REDHAT-BUG-1993070?
REDHAT-BUG-1993070 is caused by a stack buffer overflow when processing certain SPF macros in versions of libspf2 below 1.2.11.
Which versions are affected by REDHAT-BUG-1993070?
Versions of libspf2 prior to 1.2.11 are affected by REDHAT-BUG-1993070.
Can REDHAT-BUG-1993070 lead to remote code execution?
Yes, REDHAT-BUG-1993070 can potentially lead to remote code execution through maliciously crafted SPF explanation messages.