Command Injection in Sendmail - CVE-2023-51765

 

Command Injection in Sendmail - CVE-2023-51765

Published: December 27, 2023


Vulnerability identifier: #VU84797
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-51765
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to spoof email messages.

The vulnerability exists due to an error when handling line endings other than <CR><LF>. A remote attacker can spoof contents of email message and bypass SPF protection mechanism.



Affected software

Sendmail
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Micro
Legacy Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Slackware Linux
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
Anolis OS
IBM AIX
Oracle Solaris
IBM VIOS
sendmail-debugsource
sendmail-debuginfo
sendmail
sendmail-starttls
rmail
libmilter-doc
sendmail-devel
rmail-debuginfo
libmilter1_0-debuginfo
libmilter1_0
sendmail-milter
sendmail-milter-devel
sendmail-cf
sendmail-doc

How to mitigate CVE-2023-51765

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

IBM VIOS - addressed in versions 3.1.4.40, 4.1.0.20
IBM AIX - addressed in versions 7.2.5 SP08, 7.3.0, 7.3.1 SP04, 7.3.2 SP02
sendmail-debugsource - addressed in versions 8.14.9-4.9.1, 8.15.2-150000.8.12.1
sendmail-debuginfo - addressed in versions 8.14.9-4.9.1, 8.15.2-150000.8.12.1
sendmail - addressed in versions 8.14.9-4.9.1, 8.15.2-150000.8.12.1
sendmail-starttls - update to 8.15.2-150000.8.12.1
rmail - update to 8.15.2-150000.8.12.1
libmilter-doc - update to 8.15.2-150000.8.12.1
sendmail-devel - update to 8.15.2-150000.8.12.1
rmail-debuginfo - update to 8.15.2-150000.8.12.1
libmilter1_0-debuginfo - update to 8.15.2-150000.8.12.1
libmilter1_0 - update to 8.15.2-150000.8.12.1
sendmail - update to 8.18.1
sendmail - update to 8.18.1-1
sendmail-milter - update to 8.18.1-1
sendmail-milter-devel - update to 8.18.1-1
sendmail-cf - update to 8.18.1-1
sendmail-doc - update to 8.18.1-1
Oracle Solaris - addressed in versions 11.3 ESU 36.33, 11.4 SRU 68

External References

Related Security Bulletins