sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports <LF>.<CR><LF> but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with 'o' in srv_features.
{ "binaries": [ { "binary_name": "libmilter-dev", "binary_version": "8.14.4-4.1ubuntu1.1" }, { "binary_name": "libmilter1.0.1", "binary_version": "8.14.4-4.1ubuntu1.1" }, { "binary_name": "rmail", "binary_version": "8.14.4-4.1ubuntu1.1" }, { "binary_name": "sendmail", "binary_version": "8.14.4-4.1ubuntu1.1" }, { "binary_name": "sendmail-base", "binary_version": "8.14.4-4.1ubuntu1.1" }, { "binary_name": "sendmail-bin", "binary_version": "8.14.4-4.1ubuntu1.1" }, { "binary_name": "sendmail-cf", "binary_version": "8.14.4-4.1ubuntu1.1" }, { "binary_name": "sensible-mda", "binary_version": "8.14.4-4.1ubuntu1.1" } ] }
{ "binaries": [ { "binary_name": "libmilter-dev", "binary_version": "8.15.2-3" }, { "binary_name": "libmilter1.0.1", "binary_version": "8.15.2-3" }, { "binary_name": "rmail", "binary_version": "8.15.2-3" }, { "binary_name": "sendmail", "binary_version": "8.15.2-3" }, { "binary_name": "sendmail-base", "binary_version": "8.15.2-3" }, { "binary_name": "sendmail-bin", "binary_version": "8.15.2-3" }, { "binary_name": "sendmail-cf", "binary_version": "8.15.2-3" }, { "binary_name": "sensible-mda", "binary_version": "8.15.2-3" } ] }
{ "binaries": [ { "binary_name": "libmilter-dev", "binary_version": "8.15.2-10" }, { "binary_name": "libmilter1.0.1", "binary_version": "8.15.2-10" }, { "binary_name": "rmail", "binary_version": "8.15.2-10" }, { "binary_name": "sendmail", "binary_version": "8.15.2-10" }, { "binary_name": "sendmail-base", "binary_version": "8.15.2-10" }, { "binary_name": "sendmail-bin", "binary_version": "8.15.2-10" }, { "binary_name": "sendmail-cf", "binary_version": "8.15.2-10" }, { "binary_name": "sensible-mda", "binary_version": "8.15.2-10" } ] }
{ "binaries": [ { "binary_name": "libmilter-dev", "binary_version": "8.15.2-18" }, { "binary_name": "libmilter1.0.1", "binary_version": "8.15.2-18" }, { "binary_name": "rmail", "binary_version": "8.15.2-18" }, { "binary_name": "sendmail", "binary_version": "8.15.2-18" }, { "binary_name": "sendmail-base", "binary_version": "8.15.2-18" }, { "binary_name": "sendmail-bin", "binary_version": "8.15.2-18" }, { "binary_name": "sendmail-cf", "binary_version": "8.15.2-18" }, { "binary_name": "sensible-mda", "binary_version": "8.15.2-18" } ] }
{ "binaries": [ { "binary_name": "libmilter-dev", "binary_version": "8.15.2-22ubuntu3" }, { "binary_name": "libmilter1.0.1", "binary_version": "8.15.2-22ubuntu3" }, { "binary_name": "rmail", "binary_version": "8.15.2-22ubuntu3" }, { "binary_name": "sendmail", "binary_version": "8.15.2-22ubuntu3" }, { "binary_name": "sendmail-base", "binary_version": "8.15.2-22ubuntu3" }, { "binary_name": "sendmail-bin", "binary_version": "8.15.2-22ubuntu3" }, { "binary_name": "sendmail-cf", "binary_version": "8.15.2-22ubuntu3" }, { "binary_name": "sensible-mda", "binary_version": "8.15.2-22ubuntu3" } ] }