ports/128298: Security: mail/libspf2, mail/libspf2-10 buffer overflow
Jeffrey Goldberg
jeffrey at goldmark.org
Wed Oct 22 17:40:01 UTC 2008
>Number: 128298
>Category: ports
>Synopsis: Security: mail/libspf2, mail/libspf2-10 buffer overflow
>Confidential: no
>Severity: critical
>Priority: high
>Responsible: freebsd-ports-bugs
>State: open
>Quarter:
>Keywords:
>Date-Required:
>Class: sw-bug
>Submitter-Id: current-users
>Arrival-Date: Wed Oct 22 17:40:01 UTC 2008
>Closed-Date:
>Last-Modified:
>Originator: Jeffrey Goldberg
>Release: FreeBSD 7.1-PRERELEASE i386
>Organization:
>Environment:
System: FreeBSD dobby.ewd.goldmark.org 7.1-PRERELEASE FreeBSD 7.1-PRERELEASE #20: Thu Sep 4 17:09:34 CDT 2008 root at dobby.ewd.goldmark.org:/usr/obj/usr/src/sys/DOBBY i386
>Description:
According to reports (I have not verified this personally), versions
of libspf2 prior to 1.2.8 are vulnerable to exploits of a buffer
overflow due to errors in how SPF records are parsed
http://www.doxpara.com/?page_id=1256
>How-To-Repeat:
>Fix:
Upgrade to libspf2 version 1.2.8
>Release-Note:
>Audit-Trail:
>Unformatted:
More information about the freebsd-ports-bugs
mailing list