Vulnerability Description
sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports <LF>.<CR><LF> but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with 'o' in srv_features.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sendmail | Sendmail | < 8.18.0.2 |
| Freebsd | Freebsd | < 11.0 |
| Redhat | Enterprise Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2023/12/24/1Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/12/25/1Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/12/26/5Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/12/29/5Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/12/30/1Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/12/30/3Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-51765Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2255869Issue TrackingThird Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1218351Issue TrackingPatchThird Party Advisory
- https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11782.htmlTechnical Description
- https://github.com/freebsd/freebsd-src/commit/5dd76dd0cc19450133aa379ce0ce4a68aePatch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00004.html
- https://lwn.net/Articles/956533/
- https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/Technical DescriptionThird Party Advisory
- https://www.openwall.com/lists/oss-security/2023/12/21/7Mailing ListThird Party Advisory
FAQ
What is CVE-2023-51765?
CVE-2023-51765 is a vulnerability with a CVSS score of 5.3 (MEDIUM). sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowin...
How severe is CVE-2023-51765?
CVE-2023-51765 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-51765?
Check the references section above for vendor advisories and patch information. Affected products include: Sendmail Sendmail, Freebsd Freebsd, Redhat Enterprise Linux.