PT-2023-8848 · Sendmail+5 · Sendmail+5
Timo Longin
·
Published
2023-12-23
·
Updated
2024-12-18
·
CVE-2023-51765
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
sendmail versions 8.14.7 through 8.17.2
Description
The issue allows SMTP smuggling in certain configurations, enabling remote attackers to inject e-mail messages with a spoofed MAIL FROM address. This bypasses an SPF protection mechanism because sendmail supports . while other popular e-mail servers do not. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Technical details about exploitation include the use of a published exploitation technique to inject e-mail messages. The
MAIL FROM address can be spoofed, allowing attackers to bypass security mechanisms.Recommendations
For sendmail versions 8.14.7 through 8.17.2, update to version 8.18 or later, which includes 'o' in srv features to resolve the issue.
At the moment, there is no other information about additional mitigation measures for this vulnerability.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Ibm Aix
Red Os
Suse
Sendmail