[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Sendmail news for non RFC conformant change



Hi,

Could you review the following item (please cc i am not subscribed) 

  Sendmail was affected by SMTP smurgling (CVE-2023-51765).
  Remote attackers can use a published exploitation technique
  to inject e-mail messages with a spoofed MAIL FROM address,
  allowing bypass of an SPF protection mechanism.
  This occurs because sendmail supports some combinaison of
  <CR><LF><NUL>.
  .
  This particular injection vulnerability has been closed,
  unfortunatly full closure need to reject mail that
  contain NUL.
  .
  This is slighly non conformant with RFC and could
  be opt-out by setting confREJECT_NUL to 'false' 

Attachment: signature.asc
Description: This is a digitally signed message part.


Reply to: