Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other popular e-mail servers do not.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| 
 | 
Configuration 3 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2023-12-24 06:15
Updated : 2024-11-21 08:38
NVD link : CVE-2023-51766
Mitre link : CVE-2023-51766
CVE.ORG link : CVE-2023-51766
JSON object : View
Products Affected
                debian
- debian_linux
fedoraproject
- extra_packages_for_enterprise_linux
- fedora
exim
- exim
CWE
                
                    
                        
                        CWE-345
                        
            Insufficient Verification of Data Authenticity
