Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other popular e-mail servers do not.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
04 Nov 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Information
Published : 2023-12-24 06:15
Updated : 2025-11-04 19:16
NVD link : CVE-2023-51766
Mitre link : CVE-2023-51766
CVE.ORG link : CVE-2023-51766
JSON object : View
Products Affected
fedoraproject
- extra_packages_for_enterprise_linux
- fedora
debian
- debian_linux
exim
- exim
CWE
CWE-345
Insufficient Verification of Data Authenticity
