Libspf2 Project maintains a specialized library for Sender Policy Framework (SPF) validation, a narrow but strategically positioned component embedded in mail servers and filtering systems across the internet. The durable signal centers on memory-safety issues recurrent in the library's parsing logic, specifically out-of-bounds writes and integer underflow conditions that reflect the complexity of DNS record parsing and validation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libspf2 Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-42118HIGH Exim libspf2 Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Exim | May 3, 2024 | 8.8 | 55 | NO | NO |
CVE-2021-33912CRITICAL libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on | Jan 19, 2022 | 9.8 | 37 | NO | NO |
CVE-2021-33913CRITICAL libspf2 before 1.2.11 has a heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Inter | Jan 19, 2022 | 9.8 | 35 | NO | NO |
CVE-2021-20314CRITICAL Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF exp | Aug 12, 2021 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libspf2 Project.
Media articles that mention a CVE ID that affects a product developed by Libspf2 Project — matched by CVE ID, not by vendor name.