CVE-2003-0308
published 2003-05-15CVE-2003-0308: The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privileges via…
PriorityP419high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.40%
32.4th percentile
The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privileges via (1) expn, (2) checksendmail, or (3) doublebounce.pl.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | sendmail | < sendmail 8.12.9-2 (bookworm) | sendmail 8.12.9-2 (bookworm) |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | >= 0 < 8.12.9-2 | 8.12.9-2 |
| sendmail | sendmail | >= 0 < 8.12.9-2 | 8.12.9-2 |
| sendmail | sendmail | >= 0 < 8.12.9-2 | 8.12.9-2 |
| sendmail | sendmail | >= 0 < 8.12.9-2 | 8.12.9-2 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p2pv-rfm6-cxq7: expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symli
ghsa_unreviewed·2022-05-01·CVSS 7.2
CVE-2008-1078 [HIGH] CWE-59 GHSA-p2pv-rfm6-cxq7: expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symli
expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same issue as CVE-2003-0308.1.
GHSA
GHSA-c936-pgj9-534q: The Sendmail 8
ghsa_unreviewed·2022-04-29
CVE-2003-0308 [HIGH] GHSA-c936-pgj9-534q: The Sendmail 8
The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privileges via (1) expn, (2) checksendmail, or (3) doublebounce.pl.
OSV
CVE-2003-0308: The Sendmail 8
osv·2003-05-15·CVSS 7.2
CVE-2003-0308 [HIGH] CVE-2003-0308: The Sendmail 8
The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privileges via (1) expn, (2) checksendmail, or (3) doublebounce.pl.
Red Hat
am-utils: insecure usage of temporary files
vendor_redhat·2008-02-14·CVSS 7.2
CVE-2008-1078 [HIGH] am-utils: insecure usage of temporary files
am-utils: insecure usage of temporary files
expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same issue as CVE-2003-0308.1.
Statement: The risks associated with fixing this bug are greater than the low severity security risk.We therefore currently have no plans to fix this flaw in Red HatEnterprise Linux.
For more information please see the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=435420
Debian
CVE-2003-0308: sendmail - The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create tem...
vendor_debian·2003·CVSS 7.2
CVE-2003-0308 [HIGH] CVE-2003-0308: sendmail - The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create tem...
The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privileges via (1) expn, (2) checksendmail, or (3) doublebounce.pl.
Scope: local
bookworm: resolved (fixed in 8.12.9-2)
bullseye: resolved (fixed in 8.12.9-2)
forky: resolved (fixed in 8.12.9-2)
sid: resolved (fixed in 8.12.9-2)
trixie: resolved (fixed in 8.12.9-2)
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/496408http://dev.gentoo.org/~rbu/security/debiantemp/sendmail-basehttp://www.debian.org/security/2003/dsa-305http://www.openwall.com/lists/oss-security/2008/10/30/2https://bugs.gentoo.org/show_bug.cgi?id=235770http://bugs.debian.org/496408http://dev.gentoo.org/~rbu/security/debiantemp/sendmail-basehttp://www.debian.org/security/2003/dsa-305http://www.openwall.com/lists/oss-security/2008/10/30/2https://bugs.gentoo.org/show_bug.cgi?id=235770
2003-05-15
Published