Command Injection in aiosmtpd - CVE-2024-27305
Published: March 15, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform SMTP smuggling attack.
The vulnerability exists due to insufficient filtration of user supplied input when parsing headers in email messages. A remote attacker can send a specially crafted email message and smuggle or spoof e-mails with fake sender addresses, allowing advanced phishing attacks.
Affected software
openEuler
Anolis OS
python-aiosmtpd
python-aiosmtpd-help
python3-aiosmtpd
How to mitigate CVE-2024-27305
python-aiosmtpd - update to 1.4.2-2
python-aiosmtpd-help - update to 1.4.2-2
python3-aiosmtpd - update to 1.4.2-2
python3-aiosmtpd - update to 1.4.6-1