cvedb.io
CVE-2021-33913
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2022-01-19T18:15:07.830 · Last modified 2026-06-17T03:55:22.303

Summary

libspf2 before 1.2.11 has a heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of SPF_record_expand_data in spf_expand.c. The amount of overflowed data depends on the relationship between the length of an entire domain name and the length of its leftmost label. The vulnerable code may be part of the supply chain of a site's e-mail infrastructure (e.g., with additional configuration, Exim can use libspf2; the Postfix web site links to unofficial patches for use of libspf2 with Postfix; older versions of spfquery relied on libspf2) but most often is not.

Affected products

libspf2_project — libspf2

Does this affect you?

Add your gear to cvedb and we'll alert you only when libspf2_project ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.