PT-2023-8129 · Exim+4 · Exim+4

Timo Longin

·

Publicado

2023-12-22

·

Atualizado

2026-06-03

·

CVE-2023-51766

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Exim versions prior to 4.97.1
Description The issue allows SMTP smuggling in certain configurations, enabling remote attackers to inject e-mail messages with a spoofed MAIL FROM address. This can bypass an SPF protection mechanism due to Exim's support for <LF>.<CR><LF>, which some other popular e-mail servers do not support. The exploitation technique can be used to send hidden HTTP requests, effectively allowing attackers to circumvent security policies. Approximately 15,749,391 results are mainly distributed in the United States, Germany, and other countries.
Recommendations For Exim versions prior to 4.97.1, update to version 4.97.1 or later to address the SMTP smuggling issue. As a temporary workaround, consider restricting the use of the <LF>.<CR><LF> sequence in Exim configurations to minimize the risk of exploitation. Avoid using configurations that allow SMTP smuggling until the issue is resolved.

Exploit

Correção

Command Injection

Insufficient Verification of Data Authenticity

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-00108
CVE-2023-51766
DLA-3708-1
DSA-5597-1
OESA-2024-1926
OESA-2024-1927
OESA-2024-1928
OPENSUSE-SU-2024:0007-1
OPENSUSE-SU-2024:13543-1
USN-6611-1
USN-8382-1

Produtos afetados

Astra Linux
Exim
Linuxmint
Red Os
Ubuntu