sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports <LF>.<CR><LF> but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with 'o' in srv_features.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade sendmail-milter-debuginfoUpgrade sendmail-milter-develUpgrade sendmail-debugsourceUpgrade sendmailUpgrade sendmail-docUpgrade sendmail-debuginfoUpgrade sendmail-milterUpgrade sendmail-cf | Jun 9, 2026 | Dec 18, 2023 |
| Debian | — | Upgrade sendmail | Jun 17, 2024 | Dec 24, 2023 |
| Ibm Aix | — | Apply the fix or workaround for sendmail_advisory4 | Apr 12, 2024 | Dec 24, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 24, 2023 |
| Suse | — | Upgrade sendmail-develUpgrade rmailUpgrade libmilter-docUpgrade sendmailUpgrade libmilter1_0Upgrade sendmail-starttls | Mar 5, 2024 | Dec 24, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 24, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub