sk181944 - Check Point response to CVE-2023-51764 - Postfix SMTP Smuggling vulnerability
Check Point response to CVE-2023-51764 - Postfix SMTP Smuggling vulnerability
Product ClusterXL, Maestro HyperScale Firewall, Scalable Chassis, Security Gateways, VSX (Traditional)
Version R81 (EOS), R81.10 (EOS), R81.20
OS Gaia
Last Modified 2025-01-30
Symptoms
- The vulnerability involves a composition of two email services they handle non-standard forms of the SMTP "End-of-DATA" sequence in different ways.
An SMTP Client can smuggle emails inside headers of other emails between these email services.
This allows the SMTP Client to spoof the MAIL FROM and RCPT TO address and bypass SPF protection mechanism.
References:
- CVE-2023-51764
- This article applies to Security Gateway / Cluster / Scalable Platform Security Group with Mail Transfer Agent (MTA) enabled (Check Point MTA uses Postfix).
Cause
Postfix supports <LF>.<CR><LF>, which can result in email smuggling, unless configured to forbid newline (smtpd_discard_ehlo_keywords=chunking) and pipelining (smtpd_data_restrictions=reject_unauth_pipelining).
Solution
This problem was fixed ( requires manual configuration). The fix is included starting from:
- Check Point Quantum R82
- Jumbo Hotfix Accumulator for R81.20 starting from Take 54
- Jumbo Hotfix Accumulator for R81.10 starting from Take 141
- Jumbo Hotfix Accumulator for R81 starting from Take 99
- Jumbo Hotfix Accumulator for R80.40 starting from Take 211
Required Configuration after installing the required Jumbo Hotfix Accumulator:
Connect to command line on Security Gateway / each Cluster Member / Scalable Platform Security Group over SSH.
Log in to the Expert mode.
Check if the $FWDIR/conf/mta_postfix_options.cf file already exists:
ls -l $FWDIR/conf/mta_postfix_options.cf
If this file does not exist, then create it:
touch $FWDIR/conf/mta_postfix_options.cf
Edit the $FWDIR/conf/mta_postfix_options.cf file:
vi $FWDIR/conf/mta_postfix_options.cfAdd these parameters:
smtpd_forbid_unauth_pipelining = yessmtpd_forbid_bare_newline = yessmtpd_discard_ehlo_keywords = chunking,pipelining,silent-discard
Note - Refer to official Postfix Configuration Parameters page.
Save the changes in the file and exit from Vi editor.
On a Scalable Platform Security Group, copy the modified file to all Security Group Members:
asg_cp2blades $FWDIR/conf/mta_postfix_options.cfIn SmartConsole, install the Threat Prevention policy on the Security Gateway / Cluster object.
SPF must be enabled and enforced on MTA to block emails. To configure SPF follow sk146412: MTA support for Sender Policy Framework (SPF)
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level General
Status Approved by TAC
Date Created 2024-01-28
Last Modified 2025-01-30