Bug 2255852 (CVE-2023-51766) - CVE-2023-51766 exim: SMTP smuggling vulnerability
Summary: CVE-2023-51766 exim: SMTP smuggling vulnerability
Keywords:
Status: NEW
Alias: CVE-2023-51766
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2255853 2255854
Blocks: 2255562
TreeView+ depends on / blocked
 
Reported: 2023-12-25 20:01 UTC by Robb Gatica
Modified: 2024-01-24 08:41 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Robb Gatica 2023-12-25 20:01:38 UTC
Source: exim4
Version: 4.97-2
Severity: important
Tags: security upstream
Forwarded: https://bugs.exim.org/show_bug.cgi?id=3063
X-Debbugs-Cc: carnil, Debian Security Team <team.org>

Hi,

The following vulnerability was published for exim4.

CVE-2023-51766[0]:
| Exim through 4.97 allows SMTP smuggling in certain configurations.
| Remote attackers can use a published exploitation technique to
| inject e-mail messages that appear to originate from the Exim
| server, allowing bypass of an SPF protection mechanism. This occurs
| because Exim supports <LF>.<CR><LF> but some other popular e-mail
| servers do not.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-51766
    https://www.cve.org/CVERecord?id=CVE-2023-51766
[1] https://bugs.exim.org/show_bug.cgi?id=3063

Comment 1 Robb Gatica 2023-12-25 20:01:52 UTC
Created exim tracking bugs for this issue:

Affects: epel-all [bug 2255854]
Affects: fedora-all [bug 2255853]


Note You need to log in before you can comment on or make changes to this bug.