Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other popular e-mail servers do not.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2023-12-24 06:15
Updated : 2024-02-02 02:22
NVD link : CVE-2023-51766
Mitre link : CVE-2023-51766
CVE.ORG link : CVE-2023-51766
JSON object : View
Products Affected
exim
- exim
fedoraproject
- extra_packages_for_enterprise_linux
- fedora
debian
- debian_linux
CWE
CWE-345
Insufficient Verification of Data Authenticity