CVE-2008-2469

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
23/10/2008
Last modified:
09/04/2025

Description

Heap-based buffer overflow in the SPF_dns_resolv_lookup function in Spf_dns_resolv.c in libspf2 before 1.2.8 allows remote attackers to execute arbitrary code via a long DNS TXT record with a modified length field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libspf:libspf2:*:*:*:*:*:*:*:* 1.2.7 (including)
cpe:2.3:a:libspf:libspf2:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:libspf:libspf2:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:libspf:libspf2:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:libspf:libspf2:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:libspf:libspf2:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:libspf:libspf2:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:libspf:libspf2:1.2.5:*:*:*:*:*:*:*
cpe:2.3:a:libspf:libspf2:1.2.6:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools