CVE-2023-52354

NameCVE-2023-52354
Descriptionchasquid before 1.13 allows SMTP smuggling because LF-terminated lines are accepted.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
chasquid (PTS)buster0.07-1vulnerable
bullseye1.6-1vulnerable
bookworm1.11-2vulnerable
sid, trixie1.13-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
chasquidsource(unstable)1.13-1

Notes

[bookworm] - chasquid <no-dsa> (Minor issue)
[bullseye] - chasquid <no-dsa> (Minor issue)
[buster] - chasquid <postponed> (Minor issue, request smuggling)
https://blitiri.com.ar/p/chasquid/relnotes/#113-2023-12-24

Search for package or bug name: Reporting problems