Several security issues were fixed in Libspf2.. ========================================================================== Ubuntu Security Notice USN-6584-2 February 21, 2024 libspf2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in Libspf2. Software Description: - libspf2: Sender Policy Framework for SMTP authorization Details: USN-6584-1 fixed several vulnerabilities in Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. This update provides the corresponding updates for CVE-2021-33912 and CVE-2021-33913 in Ubuntu 16.04 LTS. We apologize for the inconvenience. Original advisory details: Philipp Jeitner and Haya Shulman discovered that Libspf2 incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2021-20314) It was discovered that Libspf2 incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-33912, CVE-2021-33913) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS (Available with Ubuntu Pro): libmail-spf-xs-perl 1.2.10-6ubuntu0.1~esm2 libspf2-2 1.2.10-6ubuntu0.1~esm2 libspf2-dev 1.2.10-6ubuntu0.1~esm2 spfquery 1.2.10-6ubuntu0.1~esm2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6584-2 https://ubuntu.com/security/notices/USN-6584-1 CVE-2021-33912, CVE-2021-33913 . New guidelines released for addressing libspf2 security flaws in Ubuntu. Take action to safeguard your system from possible threats.. Ubuntu Pro Updates, Security Issues, Libspf2 Fix, Remote Code Execution. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in Libspf2.. ========================================================================== Ubuntu Security Notice USN-6584-1 January 15, 2024 libspf2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in Libspf2. Software Description: - libspf2: Sender Policy Framework for SMTP authorization Details: Philipp Jeitner and Haya Shulman discovered that Libspf2 incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2021-20314) It was discovered that Libspf2 incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-33912, CVE-2021-33913) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libmail-spf-xs-perl 1.2.10-7+deb9u2build0.20.04.1 libspf2-2 1.2.10-7+deb9u2build0.20.04.1 libspf2-dev 1.2.10-7+deb9u2build0.20.04.1 spfquery 1.2.10-7+deb9u2build0.20.04.1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): libmail-spf-xs-perl 1.2.10-7ubuntu0.18.04.1~esm1 libspf2-2 1.2.10-7ubuntu0.18.04.1~esm1 libspf2-dev 1.2.10-7ubuntu0.18.04.1~esm1 spfquery 1.2.10-7ubuntu0.18.04.1~esm1 Ubuntu 16.04 LTS(Available with Ubuntu Pro): libmail-spf-xs-perl 1.2.10-6ubuntu0.1~esm1 libspf2-2 1.2.10-6ubuntu0.1~esm1 libspf2-dev 1.2.10-6ubuntu0.1~esm1 spfquery 1.2.10-6ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6584-1 CVE-2021-20314, CVE-2021-33912, CVE-2021-33913 Package Information: https://launchpad.net/ubuntu/+source/libspf2/1.2.10-7+deb9u2build0.20.04.1 . To fortify Ubuntu 20.04 against libspf2 vulnerabilities, keep your system updated, configure security protocols, audit packages, utilize IDS, replace libspf2, and backup data regularly. Libspf2 Security, Remote Code Execution Fix, Ubuntu Security Update. . Severity: Critical. LinuxSecurity.com Team
Multiple vulnerabilities have been discovered in libspf2, the worst of which can lead to remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202401-22 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libspf2: Multiple vulnerabilities Date: January 15, 2024 Bugs: #807739 ID: 202401-22 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in libspf2, the worst of which can lead to remote code execution. Background ========== libspf2 is a library that implements the Sender Policy Framework, allowing mail transfer agents to make sure that an email is authorized by the domain name that it is coming from. Affected packages ================= Package Vulnerable Unaffected ------------------- ------------ ------------ mail-filter/libspf2 < 1.2.11 > = 1.2.11 Description =========== Multiple vulnerabilities have been discovered in libspf2. Please review the CVE identifiers referenced below for details. Impact ====== Various buffer overflows have been identified that can lead to denial of service and possibly arbitrary code execution. Workaround ========== There is no known workaround at this time. Resolution ========== All libspf2 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-filter/libspf2-1.2.11" References ========== [ 1 ] CVE-2021-20314 https://nvd.nist.gov/vuln/detail/CVE-2021-20314 [ 2 ] CVE-2021-33912 https://nvd.nist.gov/vuln/detail/CVE-2021-33912 [ 3 ] CVE-2021-33913 https://nvd.nist.gov/vuln/detail/CVE-2021-33913 Availability ============ This GLSA and any updates to it are available for viewingat the Gentoo Security Website: https://security.gentoo.org/glsa/202401-22 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Patch CVE-2023-42118, plus some other fixes.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-b317dd9220 2023-11-03 18:20:20.951386 -------------------------------------------------------------------------------- Name : libspf2 Product : Fedora 39 Version : 1.2.11 Release : 11.20210922git4915c308.fc39 URL : Summary : An implementation of the SPF specification Description : libspf2 is an implementation of the SPF (Sender Policy Framework) specification as found at: https://www.ietf.org/archive/id/draft-mengwong-spf-00.txt SPF allows email systems to check SPF DNS records and make sure that an email is authorized by the administrator of the domain name that it is coming from. This prevents email forgery, commonly used by spammers, scammers, and email viruses/worms. A lot of effort has been put into making it secure by design, and a great deal of effort has been put into the regression tests. -------------------------------------------------------------------------------- Update Information: Patch CVE-2023-42118, plus some other fixes. -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 3 2023 Bojan Smojver - 1.2.11-11.20210922git4915c308 - Add fixes from pull request 47 * Mon Oct 2 2023 Bojan Smojver - 1.2.11-10.20210922git4915c308 - CVE-2023-42118 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2241536 - CVE-2023-42118 libspf2: Integer Underflow Remote Code Execution Vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2241536 [ 2 ] Bug #2241537 - CVE-2023-42118 libspf2: Integer Underflow Remote Code Execution Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2241537 -------------------------------------------------------------------------------- This update can be installed with the "dnf"update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-b317dd9220' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Patch CVE-2023-42118, plus some other fixes.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-7f01e967ad 2023-10-09 01:54:42.687350 -------------------------------------------------------------------------------- Name : libspf2 Product : Fedora 38 Version : 1.2.11 Release : 11.20210922git4915c308.fc38 URL : Summary : An implementation of the SPF specification Description : libspf2 is an implementation of the SPF (Sender Policy Framework) specification as found at: https://www.ietf.org/archive/id/draft-mengwong-spf-00.txt SPF allows email systems to check SPF DNS records and make sure that an email is authorized by the administrator of the domain name that it is coming from. This prevents email forgery, commonly used by spammers, scammers, and email viruses/worms. A lot of effort has been put into making it secure by design, and a great deal of effort has been put into the regression tests. -------------------------------------------------------------------------------- Update Information: Patch CVE-2023-42118, plus some other fixes. -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 3 2023 Bojan Smojver - 1.2.11-11.20210922git4915c308 - Add fixes from pull request 47 * Mon Oct 2 2023 Bojan Smojver - 1.2.11-10.20210922git4915c308 - CVE-2023-42118 * Thu Jul 20 2023 Fedora Release Engineering - 1.2.11-8.20210922git4915c308 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Tue Jul 11 2023 Jitka Plesnikova - 1.2.11-7.20210922git4915c308 - Perl 5.38 rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2241536 - CVE-2023-42118 libspf2: Integer Underflow Remote Code Execution Vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2241536 [ 2 ] Bug #2241537 - CVE-2023-42118 libspf2: Integer Underflow RemoteCode Execution Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2241537 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-7f01e967ad' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Patch CVE-2023-42118, plus some other fixes.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-ae340c92ea 2023-10-09 01:26:34.405082 -------------------------------------------------------------------------------- Name : libspf2 Product : Fedora 37 Version : 1.2.11 Release : 11.20210922git4915c308.fc37 URL : Summary : An implementation of the SPF specification Description : libspf2 is an implementation of the SPF (Sender Policy Framework) specification as found at: https://www.ietf.org/archive/id/draft-mengwong-spf-00.txt SPF allows email systems to check SPF DNS records and make sure that an email is authorized by the administrator of the domain name that it is coming from. This prevents email forgery, commonly used by spammers, scammers, and email viruses/worms. A lot of effort has been put into making it secure by design, and a great deal of effort has been put into the regression tests. -------------------------------------------------------------------------------- Update Information: Patch CVE-2023-42118, plus some other fixes. -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 3 2023 Bojan Smojver - 1.2.11-11.20210922git4915c308 - Add fixes from pull request 47 * Mon Oct 2 2023 Bojan Smojver - 1.2.11-10.20210922git4915c308 - CVE-2023-42118 * Thu Jul 20 2023 Fedora Release Engineering - 1.2.11-8.20210922git4915c308 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Tue Jul 11 2023 Jitka Plesnikova - 1.2.11-7.20210922git4915c308 - Perl 5.38 rebuild * Thu Jan 19 2023 Fedora Release Engineering - 1.2.11-6.20210922git4915c308 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Fri Jan 6 2023 Peter Fordham - 1.2.11-5.20210922git4915c308 - Add missing include of string.h for memset in spf_utils.c https://github.com/shevek/libspf2/issues/41 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2241536 - CVE-2023-42118 libspf2: Integer Underflow Remote Code Execution Vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2241536 [ 2 ] Bug #2241537 - CVE-2023-42118 libspf2: Integer Underflow Remote Code Execution Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2241537 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-ae340c92ea' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Two issues have been found in libspf2, a library for validating mail senders with SPF. Both issues are related to heap-based buffer overflows. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2890-1
Updated libspf2 packages fix buffer overflow. References: - https://bugs.mageia.org/show_bug.cgi?id=29396 - https://www.openwall.com/lists/oss-security/2021/08/11/6 . MGASA-2021-0454 - Updated libspf2 packages fix security vulnerability Publication date: 02 Oct 2021 URL: https://advisories.mageia.org/MGASA-2021-0454.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-20314 Updated libspf2 packages fix buffer overflow. References: - https://bugs.mageia.org/show_bug.cgi?id=29396 - https://www.openwall.com/lists/oss-security/2021/08/11/6 - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.