Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other popular e-mail servers do not.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-exim | Aug 22, 2024 | Dec 24, 2023 | |
| Amazon_linux | — | amazon-linux-upgrade-exim | Jan 24, 2024 | Dec 24, 2023 |
| Debian | debian-upgrade-exim4 | Jan 8, 2024 | Dec 24, 2023 | |
| Exim | View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗ | exim-upgrade-4_97_1 | Jan 8, 2024 | Dec 24, 2023 |
| Gentoo Linux | gentoo-linux-upgrade-mail-mta-exim | Feb 19, 2024 | Dec 24, 2023 | |
| Suse | — | suse-upgrade-eximsuse-upgrade-eximonsuse-upgrade-eximstats-html | Jan 4, 2024 | Dec 24, 2023 |
| Ubuntu | ubuntu-pro-upgrade-exim4ubuntu-pro-upgrade-exim4-baseubuntu-pro-upgrade-exim4-daemon-heavyubuntu-pro-upgrade-exim4-daemon-lightubuntu-pro-upgrade-exim4-devubuntu-pro-upgrade-eximon4ubuntu-upgrade-exim4ubuntu-upgrade-exim4-baseubuntu-upgrade-eximon4 | Jan 31, 2024 | Dec 24, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub