Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-19088
HistoryJan 25, 2022 - 12:00 a.m.

libspf2 buffer overflow vulnerability (CNVD-2022-19088)

2022-01-2500:00:00
China National Vulnerability Database
www.cnvd.org.cn
14
libspf2
buffer overflow
email systems
spf records
email forgery
spammers

EPSS

0.05

Percentile

93.0%

libspf2 is a library that allows email systems (such as Sendmail, Postfix, Exim, Zmailer, and MS Exchange) to check SPF records and ensure that an email is authorized from its domain. This prevents email forgery commonly used by spammers, scammers and email viruses/worms. libspf2 suffers from a buffer overflow vulnerability that could be exploited by an attacker to execute arbitrary code through a specific SPF DNS record.