Candidate: CVE-2008-2469 PublicDate: 2008-10-23 22:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2469 Description: Heap-based buffer overflow in the SPF_dns_resolv_lookup function in Spf_dns_resolv.c in libspf2 before 1.2.8 allows remote attackers to execute arbitrary code via a long DNS TXT record with a modified length field. Ubuntu-Description: Notes: Bugs: Priority: high Discovered-by: Assigned-to: ScottK CVSS: Patches_libspf2: upstream_libspf2: released (1.2.8) dapper_libspf2: released (1.2.5-3ubuntu0.1) gutsy_libspf2: released (1.2.5.dfsg-4ubuntu0.7.10.1) hardy_libspf2: released (1.2.5.dfsg-4ubuntu0.8.04.1) devel_libspf2: not-affected