sendmail through 8.17.2 allows SMTP... CVE-2023-51765

- AV AC AU C I A
发布: 2023-12-24
修订: 2024-01-18

sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports <LF>.<CR><LF> but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with 'o' in srv_features.

0%
暂无可用Exp或PoC
当前有4条受影响产品信息