Comment 1 for bug 2049337

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package postfix - 3.8.1-2ubuntu0.1

---------------
postfix (3.8.1-2ubuntu0.1) mantic-security; urgency=medium

  * SECURITY UPDATE: SMTP smuggling (LP: #2049337)
    - debian/patches/CVE-2023-51764.patch: introduced
      `smtpd_forbid_bare_newline`. With "smtpd_forbid_bare_newline = yes",
      the Postfix SMTP server disconnects a remote SMTP client that
      sends a line ending in a 'bare newline'.
    - CVE-2023-51764

 -- Allen Huang <email address hidden> Fri, 19 Jan 2024 12:30:34 +0000