Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20231226191528.GA6930@veps.esmtp.org>
Date: Tue, 26 Dec 2023 19:15:28 +0000
From: Claus Assmann <ml+oss@...tp.org>
To: oss-security@...ts.openwall.com
Subject: Re: New SMTP smuggling attack

On Sun, Dec 24, 2023, Marcus Meissner wrote:

> - CVE-2023-51765 sendmail

Can you update the text for this (or point me to the proper way/persons
to do this)?

1.
"sendmail through at least 8.14.7"
->
sendmail up to and including 8.17.2

2.
remove the seemingly unrelated reference to
"Merge sendmail 8.14.8 to HEAD  freebsd/freebsd-src@...76dd"

3.
Mention that 8.18 fixes the problem:
	Accept only CR LF . CR LF as end of an SMTP message as
		required by the RFCs when the new srv_features
		option 'o' is used.

sendmail 8.18.0.2 is available at
https://ftp.sendmail.org/snapshots/sendmail.8.18.0.2.tar.gz
https://ftp.sendmail.org/snapshots/sendmail.8.18.0.2.tar.gz.sig

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.