VDB

CVE-2003-0161

CVE-2003-0161 PUBLISHED CVSS 10 CRITICAL

The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.

EPSS 38.79% · 98.5th percentile

Risk Scores

CVSS 2.0
10
EPSS Score
38.79%
98.5th percentile

Affected Products

VendorProductVersions
hphp-ux11.11, 11.0.4, 10.34
n/an/an/a
hphp-ux_series_80010.20
sendmailsendmail_switch3.0.1, 2.1, 2.1.1
hphp-ux_series_70010.20
sendmailsendmail8.12, 2.6, 2.6.1
hpsis
sunsolaris2.6, 7.0, 2.5.1
compaqtru645.1a, 5.1a_pk1_bl1, 5.1a_pk2_bl2
sunsunos5.7, 5.8, 5.5.1

Timeline

  • CVE Published
  • Sep 23, 2010 PoC Published
  • Feb 4, 2022 EPSS Score
  • May 21, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Dec 19, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 16, 2023 EPSS Score
  • May 26, 2023 EPSS Score
  • Sep 9, 2023 EPSS Score
  • Nov 1, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›