Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2008-2469

Description

Heap-based buffer overflow in the SPF_dns_resolv_lookup function in Spf_dns_resolv.c in libspf2 before 1.2.8 allows remote attackers to execute arbitrary code via a long DNS TXT record with a modified length field.

POC

Reference

- http://securityreason.com/securityalert/4487

- https://bugs.launchpad.net/ubuntu/feisty/+source/libspf2/+bug/271025

- https://www.exploit-db.com/exploits/6805

Github

No PoCs found on GitHub currently.