Where
-Infinity
0

Vendor Risk Score

See how libspf2 compares to other vendors in security performance

View Risk Score →

Hi,

I recently stumbled upon something, and by sharing it here, I'm hoping that I can shed some light on it.

The libspf2 library appears to be the standard way of parsing SPF records in C, but its development has mostly stalled.

In the project's github repo, there's an unmerged pull request claiming to fix a use after free bug: https://github.com/shevek/libspf2/pull/15

Quote: "Not sure what the intention is here, but in no case should spfrecordexp point to a freed object. (Fixes crash on OpenBSD 5.9.)"

There has been no reaction to this report.

I looked briefly at the code (it zeros a pointer after it's been freed), but I was unable to see a situation where this leads to a use after free. But maybe I'm missing something.

In any case, maybe this is a warning that libspf2 appears to be effectively unmaintained.

Unrelated to this specific issue, but there has been a somewhat unresolved story about a security issue in libspf2 a while ago (also with discussions on this mailing list). As far as I can tell, the following happened: ZDI claimed to have found a security issue in libspf2, but has not shared any details: https://www.zerodayinitiative.com/advisories/ZDI-23-1472/ CVE-2023-42118 got assigned. An integer underflow was fixed in libspf2's repository in response: https://github.com/shevek/libspf2/commit/d14abff4b544cfc53a8b5ef54cbc2353866b5081 However, it is neither clear whether this is practically exploitable, nor whether it is actually the bug ZDI found. No release of libspf2 has been made since then, the fix for the Integer Underflow is not included in its latest version. Distros should probably add it to their package if they haven't done so already. ZDI never clarified what the issue they found was. (Which is, to not mince words, reckless and dangerous.)

-- Hanno Böck - Independent security researcher https://itsec.hboeck.de/ https://badkeys.info/

Severity
9.8
Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Last updated 24 July 2024

1 / 3
Source: Ubuntu
First published (updated )

On Thu, Oct 05, 2023 at 10:17:41AM +0200, Heiko Schlittermann wrote: Hi ZDI, If we want to talk to ZDI, we need to CC them explicitly - added.

ZDI - please let us all know if you have any comments on the below.

Also to ZDI, I think at this point it'd work best if you make all of the available detail on these bugs public. Will you, please? The advisories you published so far are non-specific to the point of being almost useless beyond an initial heads-up. Sorry for being so direct. zdi () trendmicro com <zdi () trendmicro com> (Mi 04 Okt 2023 23:01:37 CEST): We have received a notification from the developers that these issues have been patched. We will be happy to update our advisories once they do so. https://exim.org/static/doc/security/CVE-2023-zdi.txt

As publicly advertised, we patched only a subset of the issues. And those patches are available to the public. Unfortunately there is no confirmation from your side, whether those fixes really fix the issues.

One of the open issues is related to libspf2, which is Exim a user of, but not responsible for.

ZDI-23-1472 | ZDI-CAN-17578 | CVE-2023-42118 | Exim Bug 3032

And about exactly this libspf2 issue Salvatore asked you for information.

(As I did on Oct 1st already, along with the request for additional information on one of the other unfixed issues (DNSDB)). I didn't receive any response yet.

Best regards from Dresden/Germany Viele Gr????e aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de ---------------------------- internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} - gnupg encrypted messages are welcome --------------- key ID: F69376CE - Alexander

First published (updated )

Hi ZDI,

zdi () trendmicro com <zdi () trendmicro com> (Mi 04 Okt 2023 23:01:37 CEST): We have received a notification from the developers that these issues have been patched. We will be happy to update our advisories once they do so. https://exim.org/static/doc/security/CVE-2023-zdi.txt

As publicly advertised, we patched only a subset of the issues. And those patches are available to the public. Unfortunately there is no confirmation from your side, whether those fixes really fix the issues.

One of the open issues is related to libspf2, which is Exim a user of, but not responsible for.

ZDI-23-1472 | ZDI-CAN-17578 | CVE-2023-42118 | Exim Bug 3032

And about exactly this libspf2 issue Salvatore asked you for information.

(As I did on Oct 1st already, along with the request for additional information on one of the other unfixed issues (DNSDB)). I didn't receive any response yet.

Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de ---------------------------- internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} - gnupg encrypted messages are welcome --------------- key ID: F69376CE -

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203