Back to search
CVE-2008-2469
Published: Oct 23, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
Heap-based buffer overflow in the SPF_dns_resolv_lookup function in Spf_dns_resolv.c in libspf2 before 1.2.8 allows remote attackers to execute arbitrary code via a long DNS TXT record with a modified length field.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
32720
third-party-advisory
x_refsource_SECUNIA
6805
exploit
x_refsource_EXPLOIT-DB
32396
third-party-advisory
x_refsource_SECUNIA
31881
vdb-entry
x_refsource_BID
4487
third-party-advisory
x_refsource_SREASON
libspf2-dnstxtrecord-bo(46055)
vdb-entry
x_refsource_XF
http://up2date.astaro.com/2008/11/up2date_7305_released.html
x_refsource_CONFIRM
http://bugs.gentoo.org/show_bug.cgi?format=multiple&id=242254
x_refsource_CONFIRM
DSA-1659
vendor-advisory
x_refsource_DEBIAN
ADV-2008-2896
vdb-entry
x_refsource_VUPEN
https://bugs.launchpad.net/ubuntu/feisty/+source/libspf2/+bug/271025
x_refsource_CONFIRM
http://www.doxpara.com/?page_id=1256
x_refsource_MISC
http://www.doxpara.com/?p=1263
x_refsource_MISC
GLSA-200810-03
vendor-advisory
x_refsource_GENTOO
VU#183657
third-party-advisory
x_refsource_CERT-VN
32496
third-party-advisory
x_refsource_SECUNIA
32450
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now