5.3
CVSSv3

CVE-2023-51766

Published: 24/12/2023 Updated: 02/02/2024
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Exim prior to 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other popular e-mail servers do not.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

exim exim

fedoraproject extra packages for enterprise linux 8.0

fedoraproject extra packages for enterprise linux 9.0

fedoraproject extra packages for enterprise linux 7.0

fedoraproject fedora 38

fedoraproject fedora 39

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #1059387 exim4: CVE-2023-51766 Package: src:exim4; Maintainer for src:exim4 is Exim4 Maintainers &lt;pkg-exim4-maintainers@listsaliothdebianorg&gt;; Reported by: Salvatore Bonaccorso &lt;carnil@debianorg&gt; Date: Sun, 24 Dec 2023 08:45:04 UTC Severity: important Tags: security, upstream Found in ve ...
Exim through 497 allows SMTP smuggling in certain configurations Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism This occurs because Exim supports &lt;LF&gt;&lt;CR&gt;&lt;LF&gt; but some other popular e-mail servers do not (CV ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: Re: New SMTP smuggling attack <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Marcus Meissner &lt;meissner () ...
<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: CVE-2023-51766: Exim: SMTP smuggling <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Jeffrey Walton &lt;noloa ...

Github Repositories

smtpsmug Script to help analyze mail servers for SMTP Smuggling vulnerabilities docs smtpsmug allows sending mails to an smtp server and ending it with various malformed end of data symbol This tests whether servers are affected by SMTP Smuggling vulnerabilities Please consider this preliminary and work in progress, I am still trying to fully understand the issue myself By