CVE-2023-51764: SMTP smuggling

Bug #2049337 reported by Olaf Meeuwissen
274
This bug affects 4 people
Affects Status Importance Assigned to Milestone
postfix (Ubuntu)
Fix Released
Undecided
Allen Huang

Bug Description

I noticed this by way of a Debian stable update announcement and upgrade my Debian machines on 2024-01-10. Looking for an update for my Ubuntu 22.04LTS hosts I didn't find any.

Please address this security issue.

Links:
- https://lists.debian.org/debian-stable-announce/2023/12/msg00004.html
- https://www.postfix.org/smtp-smuggling.html

PS: According to the Postfix URL, exim and sendmail are also affected so you might want to look into that as well.

CVE References

information type: Private Security → Public Security
Changed in postfix (Ubuntu):
assignee: nobody → Allen Huang (allenpthuang)
status: New → In Progress
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package postfix - 3.8.1-2ubuntu0.1

---------------
postfix (3.8.1-2ubuntu0.1) mantic-security; urgency=medium

  * SECURITY UPDATE: SMTP smuggling (LP: #2049337)
    - debian/patches/CVE-2023-51764.patch: introduced
      `smtpd_forbid_bare_newline`. With "smtpd_forbid_bare_newline = yes",
      the Postfix SMTP server disconnects a remote SMTP client that
      sends a line ending in a 'bare newline'.
    - CVE-2023-51764

 -- Allen Huang <email address hidden> Fri, 19 Jan 2024 12:30:34 +0000

Changed in postfix (Ubuntu):
status: In Progress → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package postfix - 3.6.4-1ubuntu1.2

---------------
postfix (3.6.4-1ubuntu1.2) jammy-security; urgency=medium

  * SECURITY UPDATE: SMTP smuggling (LP: #2049337)
    - debian/patches/CVE-2023-51764.patch: introduced
      `smtpd_forbid_bare_newline`. With "smtpd_forbid_bare_newline = yes",
       the Postfix SMTP server disconnects a remote SMTP client that
       sends a line ending in a 'bare newline'.
    - CVE-2023-51764

 -- Allen Huang <email address hidden> Tue, 16 Jan 2024 15:11:43 +0000

Changed in postfix (Ubuntu):
status: In Progress → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package postfix - 3.4.13-0ubuntu1.3

---------------
postfix (3.4.13-0ubuntu1.3) focal-security; urgency=medium

  * SECURITY UPDATE: SMTP smuggling (LP: #2049337)
    - debian/patches/CVE-2023-51764.patch: introduced
      `smtpd_forbid_bare_newline`. With "smtpd_forbid_bare_newline = yes",
       the Postfix SMTP server disconnects a remote SMTP client that
       sends a line ending in a 'bare newline'.
    - CVE-2023-51764

 -- Allen Huang <email address hidden> Tue, 16 Jan 2024 16:03:32 +0000

Changed in postfix (Ubuntu):
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.