Bug 2269311 (CVE-2024-27305) - CVE-2024-27305 aio-libs/aiosmtpd: SMTP smuggling
Summary: CVE-2024-27305 aio-libs/aiosmtpd: SMTP smuggling
Keywords:
Status: NEW
Alias: CVE-2024-27305
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2269312 2269313
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-03-13 03:39 UTC by TEJ RATHI
Modified: 2024-03-13 03:39 UTC (History)
0 users

Fixed In Version: aiosmtpd 1.4.5
Doc Type: ---
Doc Text:
Aio-libs python-aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol. By exploiting SMTP smuggling, an attacker may send smuggle/spoof e-mails with fake sender addresses, allowing advanced phishing attacks.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description TEJ RATHI 2024-03-13 03:39:25 UTC
aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol. By exploiting SMTP smuggling, an attacker may send smuggle/spoof e-mails with fake sender addresses, allowing advanced phishing attacks. This issue is also existed in other SMTP software like Postfix. With the right SMTP server constellation, an attacker can send spoofed e-mails to inbound/receiving aiosmtpd instances. This issue has been addressed in version 1.4.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

https://github.com/aio-libs/aiosmtpd/commit/24b6c79c8921cf1800e27ca144f4f37023982bbb
https://github.com/aio-libs/aiosmtpd/security/advisories/GHSA-pr2m-px7j-xg65
https://www.postfix.org/smtp-smuggling.html

Comment 1 TEJ RATHI 2024-03-13 03:39:59 UTC
Created python-aiosmtpd tracking bugs for this issue:

Affects: epel-7 [bug 2269312]
Affects: fedora-all [bug 2269313]


Note You need to log in before you can comment on or make changes to this bug.