Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33793
HistoryJan 20, 2022 - 10:30 a.m.

Remote Code Execution (RCE)

2022-01-2010:30:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
remote code execution
libspf2
buffer overflow
spf_record_expand_data
unauthenticated email

EPSS

0.05

Percentile

93.0%

libspf2 is vulnerable to remote code execution. The vulnerability exists due to a heap-based buffer overflow in SPF_record_expand_data in spf_expand.c in the system allowing an attacker to execute maliciously crafted script via an unauthenticated email message.