CVE-2021-20314

CRITICAL

libspf2 < 1.2.11 - Stack Buffer Overflow via SPF Macro Processing

Title source: llm
STIX 2.1

Description

Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages.

References (5)

Core 5

Scores

CVSS v3 9.8
EPSS 0.0017
EPSS Percentile 37.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (5)
fedoraproject/fedora 33
fedoraproject/fedora 34
fedoraproject/fedora 35
libspf2/libspf2 < 1.2.11
redhat/enterprise_linux 7.0
Published Aug 12, 2021
Tracked Since Feb 18, 2026