CVE-2023-51765

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Dec 24, 2023
Updated: Jun 15, 2024
CWE ID 345

Summary

CVE-2023-51765 is a vulnerability affecting sendmail versions up to 8.17.2. It allows for SMTP smuggling in certain configurations, enabling remote attackers to inject e-mail messages with spoofed MAIL FROM addresses. This bypasses SPF protection mechanisms due to sendmail's support for <LF>.<CR><LF>, which is not common in other popular email servers. The issue is resolved in versions 8.18 and later by adding the letter 'o' in srv_features.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share