sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports <LF>.<CR><LF> but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with 'o' in srv_features.
{
"binaries": [
{
"binary_name": "libmilter-dev",
"binary_version": "8.14.4-4.1ubuntu1.1"
},
{
"binary_name": "libmilter1.0.1",
"binary_version": "8.14.4-4.1ubuntu1.1"
},
{
"binary_name": "rmail",
"binary_version": "8.14.4-4.1ubuntu1.1"
},
{
"binary_name": "sendmail",
"binary_version": "8.14.4-4.1ubuntu1.1"
},
{
"binary_name": "sendmail-base",
"binary_version": "8.14.4-4.1ubuntu1.1"
},
{
"binary_name": "sendmail-bin",
"binary_version": "8.14.4-4.1ubuntu1.1"
},
{
"binary_name": "sendmail-cf",
"binary_version": "8.14.4-4.1ubuntu1.1"
},
{
"binary_name": "sensible-mda",
"binary_version": "8.14.4-4.1ubuntu1.1"
}
]
}
{
"binaries": [
{
"binary_name": "libmilter-dev",
"binary_version": "8.15.2-3"
},
{
"binary_name": "libmilter1.0.1",
"binary_version": "8.15.2-3"
},
{
"binary_name": "rmail",
"binary_version": "8.15.2-3"
},
{
"binary_name": "sendmail",
"binary_version": "8.15.2-3"
},
{
"binary_name": "sendmail-base",
"binary_version": "8.15.2-3"
},
{
"binary_name": "sendmail-bin",
"binary_version": "8.15.2-3"
},
{
"binary_name": "sendmail-cf",
"binary_version": "8.15.2-3"
},
{
"binary_name": "sensible-mda",
"binary_version": "8.15.2-3"
}
]
}
{
"binaries": [
{
"binary_name": "libmilter-dev",
"binary_version": "8.15.2-10"
},
{
"binary_name": "libmilter1.0.1",
"binary_version": "8.15.2-10"
},
{
"binary_name": "rmail",
"binary_version": "8.15.2-10"
},
{
"binary_name": "sendmail",
"binary_version": "8.15.2-10"
},
{
"binary_name": "sendmail-base",
"binary_version": "8.15.2-10"
},
{
"binary_name": "sendmail-bin",
"binary_version": "8.15.2-10"
},
{
"binary_name": "sendmail-cf",
"binary_version": "8.15.2-10"
},
{
"binary_name": "sensible-mda",
"binary_version": "8.15.2-10"
}
]
}
{
"binaries": [
{
"binary_name": "libmilter-dev",
"binary_version": "8.15.2-18"
},
{
"binary_name": "libmilter1.0.1",
"binary_version": "8.15.2-18"
},
{
"binary_name": "rmail",
"binary_version": "8.15.2-18"
},
{
"binary_name": "sendmail",
"binary_version": "8.15.2-18"
},
{
"binary_name": "sendmail-base",
"binary_version": "8.15.2-18"
},
{
"binary_name": "sendmail-bin",
"binary_version": "8.15.2-18"
},
{
"binary_name": "sendmail-cf",
"binary_version": "8.15.2-18"
},
{
"binary_name": "sensible-mda",
"binary_version": "8.15.2-18"
}
]
}
{
"binaries": [
{
"binary_name": "libmilter-dev",
"binary_version": "8.15.2-22ubuntu3"
},
{
"binary_name": "libmilter1.0.1",
"binary_version": "8.15.2-22ubuntu3"
},
{
"binary_name": "rmail",
"binary_version": "8.15.2-22ubuntu3"
},
{
"binary_name": "sendmail",
"binary_version": "8.15.2-22ubuntu3"
},
{
"binary_name": "sendmail-base",
"binary_version": "8.15.2-22ubuntu3"
},
{
"binary_name": "sendmail-bin",
"binary_version": "8.15.2-22ubuntu3"
},
{
"binary_name": "sendmail-cf",
"binary_version": "8.15.2-22ubuntu3"
},
{
"binary_name": "sensible-mda",
"binary_version": "8.15.2-22ubuntu3"
}
]
}