-
Notifications
You must be signed in to change notification settings - Fork 28
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
anything to do about SMTP smuggling? #251
Comments
I think qmail is unaffected, but we should really test it. |
In particular |
The exploit assumes the following
This exploit doesn't apply to notmail at the moment because
Example showing notqmail's qmail-smtpd rejects bare LF. Here in the DATA section, the line
|
In the outbound direction, reading |
@DerDakon, with your agreement I'm comfortable closing this, noting in the release notes that we were never vulnerable, and filing a post-1.09 issue suggesting we also be strict about line endings before the |
IIUC, some subset of mail servers can be abused to send additional (and legitimate-looking) messages to some other subset of mail servers, so there are at least two places we need to check:
qmail-smtpd
andqmail-remote
. Maybe alsoqmail-inject
and thesendmail
wrapper?The text was updated successfully, but these errors were encountered: