Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33775
HistoryJan 20, 2022 - 6:14 a.m.

Remote Code Execution (RCE)

2022-01-2006:14:24
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
remote code execution
libspf2
spf_record_expand_data
spf_expand.c
overflow data
software security
malicious dns record

EPSS

0.023

Percentile

89.9%

libspf2 is vulnerable to remote code execution. The vulnerability exists in SPF_record_expand_data in spf_expand.c, allowing an attacker to send a malicious SPF DNS record to cause overflow data.