PT-2023-8129 · Exim+4 · Exim+4

Timo Longin

·

Published

2023-12-22

·

Updated

2026-06-03

·

CVE-2023-51766

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Exim versions prior to 4.97.1
Description The issue allows SMTP smuggling in certain configurations, enabling remote attackers to inject e-mail messages with a spoofed MAIL FROM address. This can bypass an SPF protection mechanism due to Exim's support for <LF>.<CR><LF>, which some other popular e-mail servers do not support. The exploitation technique can be used to send hidden HTTP requests, effectively allowing attackers to circumvent security policies. Approximately 15,749,391 results are mainly distributed in the United States, Germany, and other countries.
Recommendations For Exim versions prior to 4.97.1, update to version 4.97.1 or later to address the SMTP smuggling issue. As a temporary workaround, consider restricting the use of the <LF>.<CR><LF> sequence in Exim configurations to minimize the risk of exploitation. Avoid using configurations that allow SMTP smuggling until the issue is resolved.

Exploit

Fix

Command Injection

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00108
CVE-2023-51766
DLA-3708-1
DSA-5597-1
OESA-2024-1926
OESA-2024-1927
OESA-2024-1928
OPENSUSE-SU-2024:0007-1
OPENSUSE-SU-2024:13543-1
USN-6611-1
USN-8382-1

Affected Products

Astra Linux
Exim
Linuxmint
Red Os
Ubuntu