CVE-2003-0681
published 2003-10-06CVE-2003-0681: A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific…
PriorityP270high7.5CVSS 2.0
AVNACLAuNCPIPAP
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
20.08%
97.2th percentile
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
Affected
101 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| debian | sendmail | < sendmail 8.12.10-1 (bookworm) | sendmail 8.12.10-1 (bookworm) |
| gentoo | linux | — | — |
| gentoo | linux | — | — |
| gentoo | linux | — | — |
| gentoo | linux | — | — |
| gentoo | linux | — | — |
| hp | hp-ux | — | — |
| hp | hp-ux | — | — |
| hp | hp-ux | — | — |
| hp | hp-ux | — | — |
| ibm | aix | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- ·Vulnerability is limited to nonstandard ruleset configurations: 'recipient', 'final', or mailer-specific envelope recipient rulesets must be explicitly enabled for the flaw to be reachable. ↗
- ·Consequences of exploitation are officially listed as unknown; no confirmed exploit path or impact has been documented for this specific CVE. ↗
- ·The exploit code in Exploit-DB 23154 targets the prescan() function (a distinct vulnerability, BID 8641), NOT the ruleset parsing buffer overflow of CVE-2003-0681. Do not conflate the two. ↗
- ·Fixed in Sendmail 8.12.10-1 per Debian security tracker. ↗
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vulncheck7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2003-09-17·CVSS 7.5
CVE-2003-0681 [HIGH] security flaw
security flaw
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
Debian
CVE-2003-0681: sendmail - A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using...
vendor_debian·2003·CVSS 7.5
CVE-2003-0681 [HIGH] CVE-2003-0681: sendmail - A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using...
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
Scope: local
bookworm: resolved (fixed in 8.12.10-1)
bullseye: resolved (fixed in 8.12.10-1)
forky: resolved (fixed in 8.12.10-1)
sid: resolved (fixed in 8.12.10-1)
trixie: resolved (fixed in 8.12.10-1)
GHSA
GHSA-3jjj-qxx6-gqmg: A "potential buffer overflow in ruleset parsing" for Sendmail 8
ghsa_unreviewed·2022-04-29
CVE-2003-0681 [HIGH] GHSA-3jjj-qxx6-gqmg: A "potential buffer overflow in ruleset parsing" for Sendmail 8
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
OSV
CVE-2003-0681: A "potential buffer overflow in ruleset parsing" for Sendmail 8
osv·2003-10-06·CVSS 7.5
CVE-2003-0681 [HIGH] CVE-2003-0681: A "potential buffer overflow in ruleset parsing" for Sendmail 8
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
VulnCheck
sendmail advanced_message_server Out-of-bounds Write
vulncheck·2003·CVSS 7.5
CVE-2003-0681 [HIGH] sendmail advanced_message_server Out-of-bounds Write
sendmail advanced_message_server Out-of-bounds Write
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
Affected: sendmail advanced_message_server
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=a9c54f79-d780-437b-a7f5-a74960e299d5&CommunityKey=8af7f28f-02f1-4107-8639-93a60b6546d4&tab=librarydocuments
No detection rules found.
arXiv
Combining Static and Dynamic Analysis for Vulnerability Detection
arxiv_fulltext·2013-05-16
Combining Static and Dynamic Analysis for Vulnerability Detection
Combining Static and Dynamic Analysis for Vulnerability Detection
Sanjay Rawat Dumitru Ceara Laurent Mounier Marie-Laure Potet
VERIMAG laboratory
University of Grenoble (UJF)
38610 Gi\`eres, France.
\Dumitru.Ceara, Laurent.Mounier, Marie-Laure.Potet, Sanjay.Rawat\@imag.fr
## Abstract
In this paper, we present a hybrid approach for buffer overflow detection in C code. The approach makes use of static and dynamic analysis of the application under investigation. The static part consists in calculating taint dependency sequences (TDS) between user controlled inputs and vulnerable statements. This process is akin to program slice of interest to calculate tainted data- and control-flow path which exhibits the dependence between tainted program inputs and vulnerable statements in the code. Th
Bugzilla
CVE-2003-0681 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2003-0681 [HIGH] CVE-2003-0681 security flaw
CVE-2003-0681 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000742http://marc.info/?l=bugtraq&m=106383437615742&w=2http://marc.info/?l=bugtraq&m=106398718909274&w=2http://www.debian.org/security/2003/dsa-384http://www.kb.cert.org/vuls/id/108964http://www.mandriva.com/security/advisories?name=MDKSA-2003:092http://www.redhat.com/support/errata/RHSA-2003-283.htmlhttp://www.securityfocus.com/bid/8649http://www.sendmail.org/8.12.10.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/13216https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3606https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A595http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000742http://marc.info/?l=bugtraq&m=106383437615742&w=2http://marc.info/?l=bugtraq&m=106398718909274&w=2http://www.debian.org/security/2003/dsa-384http://www.kb.cert.org/vuls/id/108964http://www.mandriva.com/security/advisories?name=MDKSA-2003:092http://www.redhat.com/support/errata/RHSA-2003-283.htmlhttp://www.securityfocus.com/bid/8649http://www.sendmail.org/8.12.10.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/13216https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3606https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A595
2003-10-06
Published
Exploited in the wild