CVE-2006-1520

Publication date 22 May 2006

Last updated 17 July 2025


Ubuntu priority

Description

Format string vulnerability in ANSI C Sender Policy Framework library (libspf) before 1.0.0-p5, when debugging is enabled, allows remote attackers to execute arbitrary code via format string specifiers, possibly in an e-mail address.

Read the notes from the security team

Status

Package Ubuntu Release Status
libspf 7.10 gutsy
Not affected
7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected

Notes


fujitsu

Debian says debugging isn't enabled, so we're not affected.


Access our resources on patching vulnerabilities