CVE-2021-33912
published 2022-01-19CVE-2021-33912: libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail…
PriorityP359critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
9.64%
94.9th percentile
libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of incorrect sprintf usage in SPF_record_expand_data in spf_expand.c. The vulnerable code may be part of the supply chain of a site's e-mail infrastructure (e.g., with additional configuration, Exim can use libspf2; the Postfix web site links to unofficial patches for use of libspf2 with Postfix; older versions of spfquery relied on libspf2) but most often is not.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libspf2 | < libspf2 1.2.10-7.1 (bookworm) | libspf2 1.2.10-7.1 (bookworm) |
| libspf2 | libspf2 | >= 0 < 1.2.10-7.1~deb11u1 | 1.2.10-7.1~deb11u1 |
| libspf2 | libspf2 | >= 0 < 1.2.10-7.1 | 1.2.10-7.1 |
| libspf2 | libspf2 | >= 0 < 1.2.10-7.1 | 1.2.10-7.1 |
| libspf2 | libspf2 | >= 0 < 1.2.10-7.1 | 1.2.10-7.1 |
| libspf2 | libspf2 | >= 0 < 1.2.10-7+deb9u2build0.20.04.1 | 1.2.10-7+deb9u2build0.20.04.1 |
| libspf2 | libspf2 | >= 0 < 1.2.10-6ubuntu0.1~esm2 | 1.2.10-6ubuntu0.1~esm2 |
| libspf2 | libspf2 | >= 0 < 1.2.10-6ubuntu0.1~esm1 | 1.2.10-6ubuntu0.1~esm1 |
| libspf2 | libspf2 | >= 0 < 1.2.10-7ubuntu0.18.04.1~esm1 | 1.2.10-7ubuntu0.18.04.1~esm1 |
| libspf2_project | libspf2 | < 1.2.11 | 1.2.11 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libspf2 vulnerabilities
osv·2024-02-21·CVSS 9.8
CVE-2021-33912 [CRITICAL] libspf2 vulnerabilities
libspf2 vulnerabilities
USN-6584-1 fixed several vulnerabilities in Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. This update provides the corresponding updates for
CVE-2021-33912 and CVE-2021-33913 in Ubuntu 16.04 LTS.
We apologize for the inconvenience.
Original advisory details:
Philipp Jeitner and Haya Shulman discovered that Libspf2 incorrectly handled
certain inputs. If a user or an automated system were tricked into opening a
specially crafted input file, a remote attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. (CVE-2021-20314)
It was discovered that Libspf2 incorrectly handled certain inputs. If a user or
an automated system were tricked into opening a specially crafted input file, a
remote attacker could possibly use this issue to cause
OSV
libspf2 vulnerabilities
osv·2024-01-15·CVSS 9.8
CVE-2021-20314 [CRITICAL] libspf2 vulnerabilities
libspf2 vulnerabilities
Philipp Jeitner and Haya Shulman discovered that Libspf2 incorrectly handled
certain inputs. If a user or an automated system were tricked into opening a
specially crafted input file, a remote attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. (CVE-2021-20314)
It was discovered that Libspf2 incorrectly handled certain inputs. If a user or
an automated system were tricked into opening a specially crafted input file, a
remote attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. This issue only affected Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2021-33912, CVE-2021-33913)
GHSA
GHSA-f8wp-q2v8-9hc2: libspf2 before 1
ghsa_unreviewed·2022-01-20
CVE-2021-33912 [CRITICAL] CWE-787 GHSA-f8wp-q2v8-9hc2: libspf2 before 1
libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of incorrect sprintf usage in SPF_record_expand_data in spf_expand.c. The vulnerable code may be part of the supply chain of a site's e-mail infrastructure (e.g., with additional configuration, Exim can use libspf2; the Postfix web site links to unofficial patches for use of libspf2 with Postfix; older versions of spfquery relied on libspf2) but most often is not.
OSV
CVE-2021-33912: libspf2 before 1
osv·2022-01-19·CVSS 9.8
CVE-2021-33912 [CRITICAL] CVE-2021-33912: libspf2 before 1
libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of incorrect sprintf usage in SPF_record_expand_data in spf_expand.c. The vulnerable code may be part of the supply chain of a site's e-mail infrastructure (e.g., with additional configuration, Exim can use libspf2; the Postfix web site links to unofficial patches for use of libspf2 with Postfix; older versions of spfquery relied on libspf2) but most often is not.
Ubuntu
Libspf2 vulnerabilities
vendor_ubuntu·2024-02-21·CVSS 9.8
CVE-2021-33913 [CRITICAL] Libspf2 vulnerabilities
Title: Libspf2 vulnerabilities
Summary: Several security issues were fixed in Libspf2.
USN-6584-1 fixed several vulnerabilities in Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. This update provides the corresponding updates for
CVE-2021-33912 and CVE-2021-33913 in Ubuntu 16.04 LTS.
We apologize for the inconvenience.
Original advisory details:
Philipp Jeitner and Haya Shulman discovered that Libspf2 incorrectly handled
certain inputs. If a user or an automated system were tricked into opening a
specially crafted input file, a remote attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. (CVE-2021-20314)
It was discovered that Libspf2 incorrectly handled certain inputs. If a user or
an automated system were tricked into opening a specially crafted inpu
Ubuntu
Libspf2 vulnerabilities
vendor_ubuntu·2024-01-15·CVSS 9.8
CVE-2021-33912 [CRITICAL] Libspf2 vulnerabilities
Title: Libspf2 vulnerabilities
Summary: Several security issues were fixed in Libspf2.
Philipp Jeitner and Haya Shulman discovered that Libspf2 incorrectly handled
certain inputs. If a user or an automated system were tricked into opening a
specially crafted input file, a remote attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. (CVE-2021-20314)
It was discovered that Libspf2 incorrectly handled certain inputs. If a user or
an automated system were tricked into opening a specially crafted input file, a
remote attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. This issue only affected Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2021-33912, CVE-2021-33913)
Instructions: In general, a standard system u
Debian
CVE-2021-33912: libspf2 - libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allo...
vendor_debian·2021·CVSS 9.8
CVE-2021-33912 [CRITICAL] CVE-2021-33912: libspf2 - libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allo...
libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of incorrect sprintf usage in SPF_record_expand_data in spf_expand.c. The vulnerable code may be part of the supply chain of a site's e-mail infrastructure (e.g., with additional configuration, Exim can use libspf2; the Postfix web site links to unofficial patches for use of libspf2 with Postfix; older versions of spfquery relied on libspf2) but most often is not.
Scope: local
bookworm: resolved (fixed in 1.2.10-7.1)
bullseye: resolved (fixed in 1.2.10-7.1~deb11u1)
forky: resolved (fixed in 1.2.10-7.1)
sid: resolved (fixed in 1.2.10-7.1)
trixie: resolved (fixe
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/shevek/libspf2/tree/8131fe140704eaae695e76b5cd09e39bd1dd220bhttps://lists.debian.org/debian-lts-announce/2022/01/msg00015.htmlhttps://nathanielbennett.com/blog/libspf2-cve-jan-2022-disclosurehttps://security.gentoo.org/glsa/202401-22https://github.com/shevek/libspf2/tree/8131fe140704eaae695e76b5cd09e39bd1dd220bhttps://lists.debian.org/debian-lts-announce/2022/01/msg00015.htmlhttps://nathanielbennett.com/blog/libspf2-cve-jan-2022-disclosurehttps://security.gentoo.org/glsa/202401-22
2022-01-19
Published