CVE-2023-51766
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other popular e-mail servers do not.
Exim hasta 4.97 permite el contrabando SMTP en ciertas configuraciones. Los atacantes remotos pueden utilizar una técnica de explotación publicada para inyectar mensajes de correo electrónico que parecen originarse en el servidor Exim, permitiendo omitir un mecanismo de protección SPF. Esto ocurre porque Exim admite . pero algunos otros servidores de correo electrónico populares no lo hacen.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-12-24 CVE Reserved
- 2023-12-24 CVE Published
- 2024-02-02 EPSS Updated
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-345: Insufficient Verification of Data Authenticity
CAPEC
References (20)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2023/12/24/1 | Mailing List | |
http://www.openwall.com/lists/oss-security/2023/12/25/1 | Mailing List | |
http://www.openwall.com/lists/oss-security/2023/12/29/2 | Mailing List | |
http://www.openwall.com/lists/oss-security/2024/01/01/1 | Mailing List | |
http://www.openwall.com/lists/oss-security/2024/01/01/2 | Mailing List | |
http://www.openwall.com/lists/oss-security/2024/01/01/3 | Mailing List | |
https://bugzilla.redhat.com/show_bug.cgi?id=2255852 | Issue Tracking | |
https://exim.org/static/doc/security/CVE-2023-51766.txt | Broken Link | |
https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11782.html | Technical Description | |
https://lists.debian.org/debian-lts-announce/2024/01/msg00002.html | Mailing List | |
https://lwn.net/Articles/956533 | Third Party Advisory | |
https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide | Technical Description | |
https://www.openwall.com/lists/oss-security/2023/12/23/2 | Issue Tracking |
URL | Date | SRC |
---|---|---|
https://www.youtube.com/watch?v=V8KPV96g1To | 2024-08-02 |
URL | Date | SRC |
---|---|---|
https://git.exim.org/exim.git/commit/5bb786d5ad568a88d50d15452aacc8404047e5ca | 2024-02-02 | |
https://git.exim.org/exim.git/commit/cf1376206284f2a4f11e32d931d4aade34c206c5 | 2024-02-02 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Exim Search vendor "Exim" | Exim Search vendor "Exim" for product "Exim" | < 4.97.1 Search vendor "Exim" for product "Exim" and version " < 4.97.1" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Extra Packages For Enterprise Linux Search vendor "Fedoraproject" for product "Extra Packages For Enterprise Linux" | 7.0 Search vendor "Fedoraproject" for product "Extra Packages For Enterprise Linux" and version "7.0" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Extra Packages For Enterprise Linux Search vendor "Fedoraproject" for product "Extra Packages For Enterprise Linux" | 8.0 Search vendor "Fedoraproject" for product "Extra Packages For Enterprise Linux" and version "8.0" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Extra Packages For Enterprise Linux Search vendor "Fedoraproject" for product "Extra Packages For Enterprise Linux" | 9.0 Search vendor "Fedoraproject" for product "Extra Packages For Enterprise Linux" and version "9.0" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 38 Search vendor "Fedoraproject" for product "Fedora" and version "38" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 39 Search vendor "Fedoraproject" for product "Fedora" and version "39" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
|