oss-sec mailing list archives

Re: Re: New SMTP smuggling attack


From: Stuart Henderson <stu () spacehopper org>
Date: Fri, 22 Dec 2023 11:09:49 +0000

On 2023/12/22 11:46, Marcus Meissner wrote:
Hi,

FWIW as no CVEs were to be found yet, I filed a CVE request for Postfix now.

Not sure if we need it for others like sendmail too, as that is also
referenced by the security researchers.

I'm a little confused by sec-consult's process here. They identify a
problem affecting various pieces of software including some very widely
deployed open source software, go to the trouble of doing a coordinated
disclosure, but only do that with...looking at their timeline... gmx,
microsoft and cisco?


Current thread: