VDB

DEBIAN-CVE-2023-51765

DEBIAN-CVE-2023-51765 PUBLISHED CVSS 5.300000190734863 MEDIUM

sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports <LF>.<CR><LF> but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with 'o' in srv_features.

Risk Scores

CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected Products

VendorProductVersions
Debian:11sendmail8.15.2-22, 0, 8.15.2-22
Debian:12sendmail0, 8.17.1.9-2, 0
Debian:13sendmail0, 0, 0
Debian:14sendmail0, 0, 0

Timeline

  • Dec 24, 2023 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›