sk181944 - Check Point response to CVE-2023-51764 - Postfix SMTP Smuggling vulnerability

Check Point response to CVE-2023-51764 - Postfix SMTP Smuggling vulnerability

Product ClusterXL, Maestro HyperScale Firewall, Scalable Chassis, Security Gateways, VSX (Traditional)

Version R81 (EOS), R81.10 (EOS), R81.20

OS Gaia

Last Modified 2025-01-30

Symptoms

An SMTP Client can smuggle emails inside headers of other emails between these email services.

This allows the SMTP Client to spoof the MAIL FROM and RCPT TO address and bypass SPF protection mechanism.

References:

Cause

Postfix supports <LF>.<CR><LF>, which can result in email smuggling, unless configured to forbid newline (smtpd_discard_ehlo_keywords=chunking) and pipelining (smtpd_data_restrictions=reject_unauth_pipelining).

Solution

This problem was fixed ( requires manual configuration). The fix is included starting from:

Required Configuration after installing the required Jumbo Hotfix Accumulator:

  1. Connect to command line on Security Gateway / each Cluster Member / Scalable Platform Security Group over SSH.

  2. Log in to the Expert mode.

  3. Check if the $FWDIR/conf/mta_postfix_options.cf file already exists:

    ls -l $FWDIR/conf/mta_postfix_options.cf

If this file does not exist, then create it:

touch $FWDIR/conf/mta_postfix_options.cf

  1. Edit the $FWDIR/conf/mta_postfix_options.cf file:

    vi $FWDIR/conf/mta_postfix_options.cf

  2. Add these parameters:

    smtpd_forbid_unauth_pipelining = yes

    smtpd_forbid_bare_newline = yes

    smtpd_discard_ehlo_keywords = chunking,pipelining,silent-discard

Note - Refer to official Postfix Configuration Parameters page.

  1. Save the changes in the file and exit from Vi editor.

  2. On a Scalable Platform Security Group, copy the modified file to all Security Group Members:

    asg_cp2blades $FWDIR/conf/mta_postfix_options.cf

  3. In SmartConsole, install the Threat Prevention policy on the Security Gateway / Cluster object.

SPF must be enabled and enforced on MTA to block emails. To configure SPF follow sk146412: MTA support for Sender Policy Framework (SPF)

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level General

Status Approved by TAC

Date Created 2024-01-28

Last Modified 2025-01-30