bugs.gentoo.orgConfirmation
http://bugs.gentoo.org/show_bug.cgi?format=multiple&id=242254 CVE-2008-2469
LibSPF2 < 1.2.8 - DNS TXT Record Parsing Bug Heap Overflow (PoC)
Record summary
CVE-2008-2469 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Heap-based buffer overflow in the SPF_dns_resolv_lookup function in Spf_dns_resolv.c in libspf2 before 1.2.8 allows remote attackers to execute arbitrary code via a long DNS TXT record with a modified length field.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBLibSPF2 < 1.2.8 - DNS TXT Record Parsing Bug Heap Overflow (PoC)ExploitDB exploitby Dan KaminskyNot analyzed1 file
References
Showing 12 of 1932396Third-party advisory
http://secunia.com/advisories/32396 32450Third-party advisory
http://secunia.com/advisories/32450 32496Third-party advisory
http://secunia.com/advisories/32496 32720Third-party advisory
http://secunia.com/advisories/32720 GLSA-200810-03Vendor advisory
http://security.gentoo.org/glsa/glsa-200810-03.xml 4487Third-party advisory
http://securityreason.com/securityalert/4487 up2date.astaro.comConfirmation
http://up2date.astaro.com/2008/11/up2date_7305_released.html DSA-1659Vendor advisory
http://www.debian.org/security/2008/dsa-1659 doxpara.com
http://www.doxpara.com/?p=1263 doxpara.com
http://www.doxpara.com/?page_id=1256 VU#183657Third-party advisory
http://www.kb.cert.org/vuls/id/183657