Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other popular e-mail servers do not.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2023-12-24 06:15
Updated : 2024-01-12 03:15
NVD link : CVE-2023-51766
Mitre link : CVE-2023-51766
JSON object : View
Products Affected
fedoraproject
- extra_packages_for_enterprise_linux
- fedora
exim
- exim
CWE
CWE-345
Insufficient Verification of Data Authenticity
