place a hint on the libspf2 issue
[exim-website.git] / templates / static / doc / security / CVE-2023-zdi.txt
index a9dc5383c59e067cf7a623cf4204048db02974b8..5edb2ec0bbf7c3c8fb864e85d03e502955589872 100644 (file)
@@ -69,7 +69,9 @@ CVSS Score: 7.5
 Mitigation: Do not use the `spf` condition in your ACL
 Subsystem:  spf
 Remark:     It is debatable if this should be filed against
-            libspf2.
+            libspf2. There are hints (simon, #Exim IRC) that this
+           is related to
+           https://github.com/shevek/libspf2/pull/44
 
 ZDI-23-1473 | ZDI-CAN-17643 | CVE-2023-42219 | Exim Bug 3033
 ------------------------------------------------------------