{"id":"MGASA-2024-0270","summary":"Updated sendmail packages fix security vulnerability","details":"sendmail through 8.17.2 allows SMTP smuggling in certain configurations.\nRemote attackers can use a published exploitation technique to inject\ne-mail messages with a spoofed MAIL FROM address, allowing bypass of an\nSPF protection mechanism. This occurs because sendmail supports\n\u003cLF\u003e.\u003cCR\u003e\u003cLF\u003e but some other popular e-mail servers do not. This is\nresolved in 8.18 and later versions with 'o' in srv_features.\n(CVE-2023-51765)\n","modified":"2026-04-16T04:44:44.576726758Z","published":"2024-07-16T03:21:38Z","upstream":["CVE-2023-51765"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2024-0270.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=32700"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2023/12/21/6"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2023/12/26/5"}],"affected":[{"package":{"name":"sendmail","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/sendmail?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.17.1-4.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0270.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}