CVE-2023-51764
published 2023-12-24CVE-2023-51764: Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking…
PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
2.60%
83.6th percentile
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Postfix supports . but some other popular e-mail servers do not. To prevent attack variants (by always disallowing without ), a different solution is required, such as the smtpd_forbid_bare_newline=yes option with a Postfix minimum version of 3.5.23, 3.6.13, 3.7.9, 3.8.4, or 3.9.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | postfix | < postfix 3.7.9-0+deb12u1 (bookworm) | postfix 3.7.9-0+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_postfix_3.7.0-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_postfix_3.9.0-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_postfix_3.7.0-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_postfix_3.7.4-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| postfix | postfix | < 3.5.23 | 3.5.23 |
| postfix | postfix | >= 0 < 3.5.23-0+deb11u1 | 3.5.23-0+deb11u1 |
| postfix | postfix | >= 0 < 3.7.9-0+deb12u1 | 3.7.9-0+deb12u1 |
| postfix | postfix | >= 0 < 3.8.4-1 | 3.8.4-1 |
| postfix | postfix | >= 0 < 3.8.4-1 | 3.8.4-1 |
| postfix | postfix | >= 3.6.0 < 3.6.13 | 3.6.13 |
| postfix | postfix | >= 3.7.0 < 3.7.9 | 3.7.9 |
| postfix | postfix | >= 3.8.0 < 3.8.4 | 3.8.4 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Postfix update
vendor_ubuntu·2024-01-31
CVE-2023-51764 Postfix update
Title: Postfix update
Summary: Postfix could allow bypass of email authentication if it received
specially crafted network traffic.
USN-6591-1 fixed vulnerabilities in Postfix. A fix with less risk of
regression has been made available since the last update. This update
updates the fix and aligns with the latest configuration guidelines
regarding this vulnerability.
We apologize for the inconvenience.
Original advisory details:
Timo Longin discovered that Postfix incorrectly handled certain email line
endings. A remote attacker could possibly use this issue to bypass an email
authentication mechanism, allowing domain spoofing and potential spamming.
Please note that certain configuration changes are required to address
this issue. They are not enabled by default for backward compatib
Ubuntu
Postfix vulnerability
vendor_ubuntu·2024-01-22
CVE-2023-51764 Postfix vulnerability
Title: Postfix vulnerability
Summary: Postfix could allow bypass of email authentication if it received
specially crafted network traffic.
Timo Longin discovered that Postfix incorrectly handled certain email line
endings. A remote attacker could possibly use this issue to bypass an email
authentication mechanism, allowing domain spoofing and potential spamming.
Please note that certain configuration changes are required to address
this issue. They are not enabled by default for backward compatibility.
Information can be found at https://www.postfix.org/smtp-smuggling.html.
Instructions: After a standard system update you need to enable
smtpd_forbid_bare_newline in your configuration and reload it to make
all the necessary changes.
Red Hat
postfix: SMTP smuggling vulnerability
vendor_redhat·2023-12-18·CVSS 5.3
CVE-2023-51764 [MEDIUM] CWE-345 postfix: SMTP smuggling vulnerability
postfix: SMTP smuggling vulnerability
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Postfix supports . but some other popular e-mail servers do not. To prevent attack variants (by always disallowing without ), a different solution is required, such as the smtpd_forbid_bare_newline=yes option with a Postfix minimum version of 3.5.23, 3.6.13, 3.7.9, 3.8.4, or 3.9.
A flaw was found in some SMTP server configurations in Postfix. This flaw al
Microsoft
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in rec
vendor_msrc·2023-12-12·CVSS 5.3
CVE-2023-51764 [MEDIUM] CWE-345 Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in rec
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address allowing bypass of an SPF protection mechanism. This occurs because Postfix supports . but some other popular e-mail servers do not. To prevent attack variants (by always disallowing without ) a different solution is required such as the smtpd_forbid_bare_newline=yes option with a Postfix minimum version of 3.5.23 3.6.13 3.7.9 3.8.4 or 3.9.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affecte
Debian
CVE-2023-51764: postfix - Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_re...
vendor_debian·2023·CVSS 5.3
CVE-2023-51764 [MEDIUM] CVE-2023-51764: postfix - Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_re...
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Postfix supports . but some other popular e-mail servers do not. To prevent attack variants (by always disallowing without ), a different solution is required, such as the smtpd_forbid_bare_newline=yes option with a Postfix minimum version of 3.5.23, 3.6.13, 3.7.9, 3.8.4, or 3.9.
Scope: local
bookworm: resolved (fixed in 3.7.9-0+deb12u1)
bullseye: resolved (fixed in 3.5.23-0+deb11u1)
forky: res
GHSA
GHSA-j5jm-hg4x-w8rx: Postfix through 3
ghsa_unreviewed·2023-12-24
CVE-2023-51764 [MEDIUM] CWE-345 GHSA-j5jm-hg4x-w8rx: Postfix through 3
Postfix through 3.8.4 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages that appear to originate from the Postfix server, allowing bypass of an SPF protection mechanism. This occurs because Postfix supports . but some other popular e-mail servers do not. To prevent attack variants (by always disallowing without ), a different solution is required: the smtpd_forbid_bare_newline=yes option with a Postfix minimum version of 3.5.23, 3.6.13, 3.7.9, 3.8.4, or 3.9.
OSV
CVE-2023-51764: Postfix through 3
osv·2023-12-24·CVSS 5.3
CVE-2023-51764 [MEDIUM] CVE-2023-51764: Postfix through 3
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Postfix supports . but some other popular e-mail servers do not. To prevent attack variants (by always disallowing without ), a different solution is required, such as the smtpd_forbid_bare_newline=yes option with a Postfix minimum version of 3.5.23, 3.6.13, 3.7.9, 3.8.4, or 3.9.
Suricata
ET EXPLOIT Inbound Setup Message from SMTP Smuggling Tool
suricata·2024-01-05
CVE-2023-51764 ET EXPLOIT Inbound Setup Message from SMTP Smuggling Tool
ET EXPLOIT Inbound Setup Message from SMTP Smuggling Tool
Rule: alert smtp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Inbound Setup Message from SMTP Smuggling Tool"; flow:established,to_client; content:"From|3a 20|setup|5f|check|40|"; nocase; content:"To|3a 20|"; nocase; distance:0; content:"Subject|3a 20|SETUP|20|CHECK"; nocase; distance:0; content:"Date|3a 20|"; nocase; distance:0; content:"Message|2d|ID|3a 20|"; nocase; distance:0; content:"Your setup seems to be working! You can now proceed with smuggling tests!"; fast_pattern; nocase; distance:0; reference:cve,2023-51764; reference:url,github.com/The-Login/SMTP-Smuggling-Tools/blob/main/smtp_smuggling_scanner.py; reference:cve,2023-51766; reference:cve,2023-51765; classtype:trojan-activity; sid:2049923; rev:1; metadata:atta
Suricata
ET EXPLOIT Inbound Smuggling Message from SMTP Smuggling Tool M2
suricata·2024-01-05
CVE-2023-51764 ET EXPLOIT Inbound Smuggling Message from SMTP Smuggling Tool M2
ET EXPLOIT Inbound Smuggling Message from SMTP Smuggling Tool M2
Rule: alert smtp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Inbound Smuggling Message from SMTP Smuggling Tool M2"; flow:established,to_client; content:"From|3a 20|smuggled|40|"; nocase; content:"To|3a 20|"; nocase; distance:0; content:"Subject|3a 20|SMUGGLED|20|EMAIL"; nocase; distance:0; content:"Date|3a 20|"; nocase; distance:0; content:"Message|2d|ID|3a 20|"; nocase; distance:0; content:"SMUGGLING WORKS with"; nocase; distance:0; content:"as|20 22|fake|22 20|end|2d|of|2d|data|20|sequence|21|"; fast_pattern; nocase; distance:0; reference:cve,2023-51764; reference:url,github.com/The-Login/SMTP-Smuggling-Tools/blob/main/smtp_smuggling_scanner.py; reference:cve,2023-51766; reference:cve,2023-51765; classtype:trojan-
Suricata
ET EXPLOIT Inbound Smuggling Message from SMTP Smuggling Tool M1
suricata·2024-01-05
CVE-2023-51764 ET EXPLOIT Inbound Smuggling Message from SMTP Smuggling Tool M1
ET EXPLOIT Inbound Smuggling Message from SMTP Smuggling Tool M1
Rule: alert smtp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Inbound Smuggling Message from SMTP Smuggling Tool M1"; flow:established,to_client; content:"From|3a 20|test|40|"; nocase; content:"To|3a 20|"; nocase; distance:0; content:"Subject|3a 20|CHECK|20|EMAIL"; nocase; distance:0; content:"Date|3a 20|"; nocase; distance:0; content:"Message|2d|ID|3a 20|"; nocase; distance:0; content:"TESTING"; nocase; distance:0; content:"as|20 22|fake|22 20|end|2d|of|2d|data|20|sequence|21|"; fast_pattern; nocase; distance:0; reference:cve,2023-51764; reference:url,github.com/The-Login/SMTP-Smuggling-Tools/blob/main/smtp_smuggling_scanner.py; reference:cve,2023-51766; reference:cve,2023-51765; classtype:trojan-activity; sid:204992
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2023/12/24/1http://www.openwall.com/lists/oss-security/2023/12/25/1http://www.openwall.com/lists/oss-security/2024/05/09/3https://access.redhat.com/security/cve/CVE-2023-51764https://bugzilla.redhat.com/show_bug.cgi?id=2255563https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11782.htmlhttps://github.com/duy-31/CVE-2023-51764https://github.com/eeenvik1/CVE-2023-51764https://lists.debian.org/debian-lts-announce/2024/01/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JQ5WXFCW2N6G2PH3JXDTYW5PH5EBQEGO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QRLF5SOS7TP5N7FQSEK2NFNB44ISVTZC/https://lwn.net/Articles/956533/https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/https://www.openwall.com/lists/oss-security/2024/01/22/1https://www.postfix.org/announcements/postfix-3.8.5.htmlhttps://www.postfix.org/smtp-smuggling.htmlhttps://www.youtube.com/watch?v=V8KPV96g1Tohttp://www.openwall.com/lists/oss-security/2023/12/24/1http://www.openwall.com/lists/oss-security/2023/12/25/1http://www.openwall.com/lists/oss-security/2024/05/09/3https://access.redhat.com/security/cve/CVE-2023-51764https://bugzilla.redhat.com/show_bug.cgi?id=2255563https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11782.htmlhttps://github.com/duy-31/CVE-2023-51764https://github.com/eeenvik1/CVE-2023-51764https://lists.debian.org/debian-lts-announce/2024/01/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JQ5WXFCW2N6G2PH3JXDTYW5PH5EBQEGO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QRLF5SOS7TP5N7FQSEK2NFNB44ISVTZC/https://lists.fedoraproject.org/archives/list/[email protected]/message/JQ5WXFCW2N6G2PH3JXDTYW5PH5EBQEGO/https://lists.fedoraproject.org/archives/list/[email protected]/message/QRLF5SOS7TP5N7FQSEK2NFNB44ISVTZC/https://lwn.net/Articles/956533/https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/https://www.openwall.com/lists/oss-security/2024/01/22/1https://www.postfix.org/announcements/postfix-3.8.5.htmlhttps://www.postfix.org/smtp-smuggling.htmlhttps://www.youtube.com/watch?v=V8KPV96g1To
2023-12-24
Published