CVE-2023-51765
published 2023-12-24CVE-2023-51765: sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.07%
61.2th percentile
sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports . but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with 'o' in srv_features.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sendmail | < sendmail 8.17.1.9-2+deb12u1 (bookworm) | sendmail 8.17.1.9-2+deb12u1 (bookworm) |
| freebsd | freebsd | < 11.0 | 11.0 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| sendmail | sendmail | < 8.18.0.2 | 8.18.0.2 |
| sendmail | sendmail | >= 0 < 8.15.2-22+deb11u1 | 8.15.2-22+deb11u1 |
| sendmail | sendmail | >= 0 < 8.17.1.9-2+deb12u1 | 8.17.1.9-2+deb12u1 |
| sendmail | sendmail | >= 0 < 8.18.1-1 | 8.18.1-1 |
| sendmail | sendmail | >= 0 < 8.18.1-1 | 8.18.1-1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
sendmail: SMTP smuggling vulnerability
vendor_redhat·2023-12-18·CVSS 5.3
CVE-2023-51765 [MEDIUM] CWE-345 sendmail: SMTP smuggling vulnerability
sendmail: SMTP smuggling vulnerability
sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports . but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with 'o' in srv_features.
A flaw was found in some SMTP server configurations in Sendmail. This issue may allow a remote attacker to break out of the email message data to "smuggle" SMTP commands and send spoofed emails that pass SPF checks.
Statement: The Sendmail vulnerability allowing SMTP smuggling is deemed moderate due to its impact on SPF protection mechanisms and specific cond
Debian
CVE-2023-51765: sendmail - sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote ...
vendor_debian·2023·CVSS 5.3
CVE-2023-51765 [MEDIUM] CVE-2023-51765: sendmail - sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote ...
sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports . but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with 'o' in srv_features.
Scope: local
bookworm: resolved (fixed in 8.17.1.9-2+deb12u1)
bullseye: resolved (fixed in 8.15.2-22+deb11u1)
forky: resolved (fixed in 8.18.1-1)
sid: resolved (fixed in 8.18.1-1)
trixie: resolved (fixed in 8.18.1-1)
OSV
CVE-2023-51765: sendmail through 8
osv·2023-12-24·CVSS 5.3
CVE-2023-51765 [MEDIUM] CVE-2023-51765: sendmail through 8
sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports . but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with 'o' in srv_features.
GHSA
GHSA-5rcq-25vc-g8qr: sendmail through at least 8
ghsa_unreviewed·2023-12-24
CVE-2023-51765 [MEDIUM] CWE-345 GHSA-5rcq-25vc-g8qr: sendmail through at least 8
sendmail through at least 8.14.7 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages that appear to originate from the sendmail server, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports . but some other popular e-mail servers do not.
Suricata
ET EXPLOIT Inbound Setup Message from SMTP Smuggling Tool
suricata·2024-01-05
CVE-2023-51764 ET EXPLOIT Inbound Setup Message from SMTP Smuggling Tool
ET EXPLOIT Inbound Setup Message from SMTP Smuggling Tool
Rule: alert smtp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Inbound Setup Message from SMTP Smuggling Tool"; flow:established,to_client; content:"From|3a 20|setup|5f|check|40|"; nocase; content:"To|3a 20|"; nocase; distance:0; content:"Subject|3a 20|SETUP|20|CHECK"; nocase; distance:0; content:"Date|3a 20|"; nocase; distance:0; content:"Message|2d|ID|3a 20|"; nocase; distance:0; content:"Your setup seems to be working! You can now proceed with smuggling tests!"; fast_pattern; nocase; distance:0; reference:cve,2023-51764; reference:url,github.com/The-Login/SMTP-Smuggling-Tools/blob/main/smtp_smuggling_scanner.py; reference:cve,2023-51766; reference:cve,2023-51765; classtype:trojan-activity; sid:2049923; rev:1; metadata:atta
Suricata
ET EXPLOIT Inbound Smuggling Message from SMTP Smuggling Tool M2
suricata·2024-01-05
CVE-2023-51764 ET EXPLOIT Inbound Smuggling Message from SMTP Smuggling Tool M2
ET EXPLOIT Inbound Smuggling Message from SMTP Smuggling Tool M2
Rule: alert smtp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Inbound Smuggling Message from SMTP Smuggling Tool M2"; flow:established,to_client; content:"From|3a 20|smuggled|40|"; nocase; content:"To|3a 20|"; nocase; distance:0; content:"Subject|3a 20|SMUGGLED|20|EMAIL"; nocase; distance:0; content:"Date|3a 20|"; nocase; distance:0; content:"Message|2d|ID|3a 20|"; nocase; distance:0; content:"SMUGGLING WORKS with"; nocase; distance:0; content:"as|20 22|fake|22 20|end|2d|of|2d|data|20|sequence|21|"; fast_pattern; nocase; distance:0; reference:cve,2023-51764; reference:url,github.com/The-Login/SMTP-Smuggling-Tools/blob/main/smtp_smuggling_scanner.py; reference:cve,2023-51766; reference:cve,2023-51765; classtype:trojan-
Suricata
ET EXPLOIT Inbound Smuggling Message from SMTP Smuggling Tool M1
suricata·2024-01-05
CVE-2023-51764 ET EXPLOIT Inbound Smuggling Message from SMTP Smuggling Tool M1
ET EXPLOIT Inbound Smuggling Message from SMTP Smuggling Tool M1
Rule: alert smtp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Inbound Smuggling Message from SMTP Smuggling Tool M1"; flow:established,to_client; content:"From|3a 20|test|40|"; nocase; content:"To|3a 20|"; nocase; distance:0; content:"Subject|3a 20|CHECK|20|EMAIL"; nocase; distance:0; content:"Date|3a 20|"; nocase; distance:0; content:"Message|2d|ID|3a 20|"; nocase; distance:0; content:"TESTING"; nocase; distance:0; content:"as|20 22|fake|22 20|end|2d|of|2d|data|20|sequence|21|"; fast_pattern; nocase; distance:0; reference:cve,2023-51764; reference:url,github.com/The-Login/SMTP-Smuggling-Tools/blob/main/smtp_smuggling_scanner.py; reference:cve,2023-51766; reference:cve,2023-51765; classtype:trojan-activity; sid:204992
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2023/12/24/1http://www.openwall.com/lists/oss-security/2023/12/25/1http://www.openwall.com/lists/oss-security/2023/12/26/5http://www.openwall.com/lists/oss-security/2023/12/29/5http://www.openwall.com/lists/oss-security/2023/12/30/1http://www.openwall.com/lists/oss-security/2023/12/30/3https://access.redhat.com/security/cve/CVE-2023-51765https://bugzilla.redhat.com/show_bug.cgi?id=2255869https://bugzilla.suse.com/show_bug.cgi?id=1218351https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11782.htmlhttps://github.com/freebsd/freebsd-src/commit/5dd76dd0cc19450133aa379ce0ce4a68ae07fb39#diff-afdf514b32ac88004952c11660c57bc96c3d8b2234007c1cbd8d7ed7fd7935cchttps://lists.debian.org/debian-lts-announce/2024/06/msg00004.htmlhttps://lwn.net/Articles/956533/https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/https://www.openwall.com/lists/oss-security/2023/12/21/7https://www.openwall.com/lists/oss-security/2023/12/22/7https://www.youtube.com/watch?v=V8KPV96g1Tohttp://www.openwall.com/lists/oss-security/2023/12/24/1http://www.openwall.com/lists/oss-security/2023/12/25/1http://www.openwall.com/lists/oss-security/2023/12/26/5http://www.openwall.com/lists/oss-security/2023/12/29/5http://www.openwall.com/lists/oss-security/2023/12/30/1http://www.openwall.com/lists/oss-security/2023/12/30/3https://access.redhat.com/security/cve/CVE-2023-51765https://bugzilla.redhat.com/show_bug.cgi?id=2255869https://bugzilla.suse.com/show_bug.cgi?id=1218351https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11782.htmlhttps://github.com/freebsd/freebsd-src/commit/5dd76dd0cc19450133aa379ce0ce4a68ae07fb39#diff-afdf514b32ac88004952c11660c57bc96c3d8b2234007c1cbd8d7ed7fd7935cchttps://lists.debian.org/debian-lts-announce/2024/06/msg00004.htmlhttps://lwn.net/Articles/956533/https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/https://www.openwall.com/lists/oss-security/2023/12/21/7https://www.openwall.com/lists/oss-security/2023/12/22/7https://www.youtube.com/watch?v=V8KPV96g1To
2023-12-24
Published