Описание
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
A flaw was found in the .NET runtime (System.Net.Mail) in how email address data is parsed. Improper neutralization of special characters, specifically carriage return and line feed (CR/LF) sequences, may allow specially crafted email address input to be interpreted incorrectly. An attacker could exploit this issue to perform email spoofing by injecting additional headers or altering how the email address is processed during SMTP operations
Отчет
This Important flaw in the .NET runtime's System.Net.Mail component affects Red Hat Enterprise Linux and Red Hat Hardened Images. Improper neutralization of carriage return and line feed sequences during email address parsing can lead to SMTP command or header injection, enabling email spoofing in applications utilizing the affected .NET versions for SMTP operations. The impact is primarily related to how email data is handled and interpreted. By injecting crafted header content, an attacker may influence the structure of email messages and potentially expose sensitive information included in those messages to unintended recipients.
Меры по смягчению последствий
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
Microsoft Security Advisory CVE-2026-32178 – .NET Spoofing Vulnerability
Уязвимость программной платформы .NET, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю проводить спуфинг-атаки
EPSS
7.5 High
CVSS3