Debian 10225 Published by

A libspf2 security update has been released for Debian GNU/Linux 8 Extended LTS to address two issues related to heap-based buffer overflows.



ELA-544-1 libspf2 security update

Package libspf2
Version 1.2.10-5+deb8u2
Related CVEs CVE-2021-33912 CVE-2021-33913

Two issues have been found in libspf2, a library for validating mail senders with SPF. Both issues are related to heap-based buffer overflows.

For Debian 8 jessie, these problems have been fixed in version 1.2.10-5+deb8u2.

We recommend that you upgrade your libspf2 packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-544-1 libspf2 security update