VDB
CVE-2003-0161
CVE-2003-0161
PUBLISHED
CVSS 10 CRITICAL
The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.
EPSS 38.79% · 98.5th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
38.79%
98.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| hp | hp-ux | 11.11, 11.0.4, 10.34 |
| n/a | n/a | n/a |
| hp | hp-ux_series_800 | 10.20 |
| sendmail | sendmail_switch | 3.0.1, 2.1, 2.1.1 |
| hp | hp-ux_series_700 | 10.20 |
| sendmail | sendmail | 8.12, 2.6, 2.6.1 |
| hp | sis | |
| sun | solaris | 2.6, 7.0, 2.5.1 |
| compaq | tru64 | 5.1a, 5.1a_pk1_bl1, 5.1a_pk2_bl2 |
| sun | sunos | 5.7, 5.8, 5.5.1 |
Timeline
- CVE Published
- Sep 23, 2010 PoC Published
- Feb 4, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 16, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
- Nov 1, 2023 EPSS Score
References
- 20030401 Immunix Secured OS 7+ openssl update mailing-list
- CLA-2003:614 vendor-advisory
- SCOSA-2004.11 vendor-advisory
- 20030520 [Fwd: 127 Research and Development: 127 Day!] mailing-list
- 7230 vdb
- CSSA-2003-016.0 vendor-advisory
- RHSA-2003:121 vendor-advisory
- 20030329 sendmail 8.12.9 available mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2003-0161 advisory
- http://marc.info/?l=bugtraq&m=104897487512238&w=2 url
- http://marc.info/?l=bugtraq&m=104914999806315&w=2 url
- ftp://patches.sgi.com/support/free/security/advisories/20030401-01-P technical
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-March/004295.html technical
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-52620-1 technical
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-52700-1 technical
- http://www.debian.org/security/2003/dsa-278 technical
- http://www.debian.org/security/2003/dsa-290 technical
- http://www.gentoo.org/security/en/glsa/glsa-200303-27.xml technical
- http://www.kb.cert.org/vuls/id/897604 advisory
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:07.sendmail.asc technical
…and 5 more