CVE-2003-0694

10 documents8 sources
Severity
10.0CRITICAL
EPSS
76.1%
top 1.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 6
Latest updateMay 3

Description

The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages17 packages

Debiansendmail< 8.12.10-1+3
NVDsendmail/sendmail33 versions+32
NVDsendmail/sendmail_pro8.9.2, 8.9.3+1
NVDsendmail/sendmail_switch16 versions+15

Also affects: Netbsd 1.4.3, 1.5, 1.5.1, 1.5.2, 1.5.3, 1.6, 1.6.1, Freebsd 3.0, 4.0, 4.3, 4.4, 4.5, 4.6, 4.7, 4.8, 4.9, 5.0, 5.1

Patches

🔴Vulnerability Details

4
GHSA
GHSA-9g2f-xcj6-7657: The prescan function in Sendmail 82022-05-03
OSV
CVE-2003-0694: The prescan function in Sendmail 82003-10-06
CVEList
CVE-2003-0694: The prescan function in Sendmail 82003-09-18
VulnCheck
Sendmail 8.12.9 prescan Remote Code Execution2003

📋Vendor Advisories

2
Red Hat
security flaw2003-09-17
Debian
CVE-2003-0694: sendmail - The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbit...2003

💬Community

3
Bugzilla
CVE-2003-0694 security flaw2018-08-16
Bugzilla
CAN-2003-0694 Sendmail possible remote exploit2003-09-17
Bugzilla
CAN-2003-0694 Sendmail possible remote exploit2003-09-17
CVE-2003-0694 (CRITICAL CVSS 10) | The prescan function in Sendmail 8. | cvebase.io