Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other popular e-mail servers do not.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade exim | Aug 22, 2024 | Dec 24, 2023 |
| Amazon_linux | — | Upgrade exim | Jan 24, 2024 | Dec 24, 2023 |
| Debian | — | Upgrade exim4 | Jan 8, 2024 | Dec 24, 2023 |
| Exim | — | Upgrade Exim to version 4.97.1 | Jan 8, 2024 | Dec 24, 2023 |
| Gentoo Linux | — | Upgrade mail-mta/exim. | Feb 19, 2024 | Dec 24, 2023 |
| Suse | — | Upgrade eximUpgrade eximstats-htmlUpgrade eximon | Jan 4, 2024 | Dec 24, 2023 |
| Ubuntu | — | Upgrade eximon4Upgrade exim4-base (Ubuntu Pro)Upgrade exim4-daemon-heavy (Ubuntu Pro)Upgrade exim4-baseUpgrade exim4Upgrade exim4 (Ubuntu Pro)Upgrade exim4-dev (Ubuntu Pro)Upgrade eximon4 (Ubuntu Pro)Upgrade exim4-daemon-light (Ubuntu Pro) | Jan 31, 2024 | Dec 24, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub