{"id":"CVE-2023-51765","details":"sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports \u003cLF\u003e.\u003cCR\u003e\u003cLF\u003e but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with 'o' in srv_features.","modified":"2026-08-12T03:51:30.482519750Z","published":"2023-12-24T00:00:00Z","related":["SUSE-SU-2024:0742-1","SUSE-SU-2024:0743-1","openSUSE-SU-2024:13658-1"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/51xxx/CVE-2023-51765.json","unresolved_ranges":[{"extracted_events":[{"fixed":"8.17.2"}],"source":"DESCRIPTION"}]},"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2023-51765"},{"type":"WEB","url":"https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11782.html"},{"type":"WEB","url":"https://lwn.net/Articles/956533/"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2023/12/21/7"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2023/12/22/7"},{"type":"WEB","url":"https://www.youtube.com/watch?v=V8KPV96g1To"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/51xxx/CVE-2023-51765.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-51765"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2255869"},{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=1218351"},{"type":"FIX","url":"https://github.com/freebsd/freebsd-src/commit/5dd76dd0cc19450133aa379ce0ce4a68ae07fb39#diff-afdf514b32ac88004952c11660c57bc96c3d8b2234007c1cbd8d7ed7fd7935cc"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/12/24/1"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/12/25/1"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/12/26/5"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/12/29/5"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/12/30/1"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/12/30/3"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00004.html"},{"type":"ARTICLE","url":"https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/freebsd/freebsd-src","events":[{"introduced":"0"},{"fixed":"671fb7df97631020c42ce55527dc49fffe0656b7"},{"introduced":"a4d3b78df842614c46b116fc5a6f470be637dccd"},{"fixed":"5dd76dd0cc19450133aa379ce0ce4a68ae07fb39"}],"database_specific":{"cpe":["cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"11.0"},{"introduced":"8.0"},{"last_affected":"8.0"},{"introduced":"9.0"},{"last_affected":"9.0"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["8.0","9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-51765.json"}}],"schema_version":"1.9.0"}