PT-2024-21808 · Postfix+1 · Postfix+1

The-Login

·

Published

2024-03-12

·

Updated

2025-01-22

·

CVE-2024-27305

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions aiosmtpd versions prior to 1.4.5
Description aiosmtpd is vulnerable to inbound SMTP smuggling, a novel vulnerability based on interpretation differences of the SMTP protocol. By exploiting this issue, an attacker may send spoofed e-mails with fake sender addresses, allowing advanced phishing attacks. This issue also exists in other SMTP software like Postfix. With the right SMTP server constellation, an attacker can send spoofed e-mails to inbound/receiving aiosmtpd instances.
Recommendations For versions prior to 1.4.5, upgrade to version 1.4.5 or later to address the issue. As a temporary workaround, consider restricting access to the SMTP server to minimize the risk of exploitation. There are no known workarounds for this vulnerability.

Exploit

Fix

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2024-27305
GHSA-PR2M-PX7J-XG65
OESA-2024-1276
OESA-2024-1320
OESA-2024-1321
OESA-2024-1322
OPENSUSE-SU-2024:0243-1
OPENSUSE-SU-2024:13774-1
PYSEC-2024-221

Affected Products

Postfix
Aiosmtpd