CVE-2003-0688
published 2003-10-20CVE-2003-0688: The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.56%
88.1th percentile
The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| compaq | tru64 | — | — |
| compaq | tru64 | — | — |
| debian | sendmail | < sendmail 8.12.9 (bookworm) | sendmail 8.12.9 (bookworm) |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| openbsd | openbsd | — | — |
| redhat | sendmail | — | — |
| redhat | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | >= 0 < 8.12.9 | 8.12.9 |
| sendmail | sendmail | >= 0 < 8.12.9 | 8.12.9 |
| sendmail | sendmail | >= 0 < 8.12.9 | 8.12.9 |
| sendmail | sendmail | >= 0 < 8.12.9 | 8.12.9 |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2003-08-25·CVSS 5.0
CVE-2003-0688 [MEDIUM] security flaw
security flaw
The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.
Debian
CVE-2003-0688: sendmail - The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" featu...
vendor_debian·2003·CVSS 5.0
CVE-2003-0688 [MEDIUM] CVE-2003-0688: sendmail - The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" featu...
The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.
Scope: local
bookworm: resolved (fixed in 8.12.9)
bullseye: resolved (fixed in 8.12.9)
forky: resolved (fixed in 8.12.9)
sid: resolved (fixed in 8.12.9)
trixie: resolved (fixed in 8.12.9)
GHSA
GHSA-g82v-vwh4-vpjc: The DNS map code in Sendmail 8
ghsa_unreviewed·2022-05-03
CVE-2003-0688 [MEDIUM] GHSA-g82v-vwh4-vpjc: The DNS map code in Sendmail 8
The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.
OSV
CVE-2003-0688: The DNS map code in Sendmail 8
osv·2003-10-20·CVSS 5.0
CVE-2003-0688 [MEDIUM] CVE-2003-0688: The DNS map code in Sendmail 8
The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.
No detection rules found.
No public exploits indexed.
ftp://patches.sgi.com/support/free/security/advisories/20030803-01-Phttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000727http://www.kb.cert.org/vuls/id/993452http://www.mandriva.com/security/advisories?name=MDKSA-2003:086http://www.novell.com/linux/security/advisories/2003_035_sendmail.htmlhttp://www.redhat.com/support/errata/RHSA-2003-265.htmlhttp://www.sendmail.org/dnsmap1.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A597ftp://patches.sgi.com/support/free/security/advisories/20030803-01-Phttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000727http://www.kb.cert.org/vuls/id/993452http://www.mandriva.com/security/advisories?name=MDKSA-2003:086http://www.novell.com/linux/security/advisories/2003_035_sendmail.htmlhttp://www.redhat.com/support/errata/RHSA-2003-265.htmlhttp://www.sendmail.org/dnsmap1.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A597
2003-10-20
Published