CVE-2003-0694
published 2003-10-06CVE-2003-0694: The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr…
PriorityP269critical10CVSS 2.0
AVNACLAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
60.19%
99.0th percentile
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
Affected
149 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| compaq | tru64 | — | — |
| compaq | tru64 | — | — |
| compaq | tru64 | — | — |
| compaq | tru64 | — | — |
| compaq | tru64 | — | — |
| compaq | tru64 | — | — |
| compaq | tru64 | — | — |
| compaq | tru64 | — | — |
| compaq | tru64 | — | — |
| compaq | tru64 | — | — |
| compaq | tru64 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor SMTP header parsing in Sendmail for buffer overflow attempts targeting the prescan() function, particularly malformed address fields processed by parseaddr.c. ↗
- →Inspect inbound SMTP traffic for address fields containing 0x5c (backslash) and 0x00 (null) byte sequences, which are the constrained byte values usable in exploitation of this vulnerability. ↗
- ·Exploitation is constrained to only 0x5c and 0x00 bytes within the prescan function, significantly limiting the ability to achieve arbitrary code execution (more likely a DoS/memory corruption outcome). ↗
- ·The Metasploit module for this CVE is classified as auxiliary/dos (denial of service), not a full remote code execution exploit, reflecting the byte constraint limitation. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vulncheck10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9g2f-xcj6-7657: The prescan function in Sendmail 8
ghsa_unreviewed·2022-05-03
CVE-2003-0694 [HIGH] GHSA-9g2f-xcj6-7657: The prescan function in Sendmail 8
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
OSV
CVE-2003-0694: The prescan function in Sendmail 8
osv·2003-10-06·CVSS 10.0
CVE-2003-0694 [CRITICAL] CVE-2003-0694: The prescan function in Sendmail 8
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
VulnCheck
Sendmail 8.12.9 prescan Remote Code Execution
vulncheck·2003·CVSS 10.0
CVE-2003-0694 [CRITICAL] Sendmail 8.12.9 prescan Remote Code Execution
Sendmail 8.12.9 prescan Remote Code Execution
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
Affected: sendmail advanced_message_server
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=a9c54f79-d780-437b-a7f5-a74960e299d5&CommunityKey=8af7f28f-02f1-4107-8639-93a60b6546d4&tab=librarydocuments
Red Hat
security flaw
vendor_redhat·2003-09-17·CVSS 10.0
CVE-2003-0694 [CRITICAL] security flaw
security flaw
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
Debian
CVE-2003-0694: sendmail - The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbit...
vendor_debian·2003·CVSS 10.0
CVE-2003-0694 [CRITICAL] CVE-2003-0694: sendmail - The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbit...
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
Scope: local
bookworm: resolved (fixed in 8.12.10-1)
bullseye: resolved (fixed in 8.12.10-1)
forky: resolved (fixed in 8.12.10-1)
sid: resolved (fixed in 8.12.10-1)
trixie: resolved (fixed in 8.12.10-1)
No detection rules found.
Bugzilla
CVE-2003-0694 security flaw
bugzilla·2018-08-16·CVSS 10.0
CVE-2003-0694 [CRITICAL] CVE-2003-0694 security flaw
CVE-2003-0694 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
Bugzilla
CAN-2003-0694 Sendmail possible remote exploit
bugzilla·2003-09-17
[MEDIUM] CAN-2003-0694 Sendmail possible remote exploit
CAN-2003-0694 Sendmail possible remote exploit
There is a bug in the prescan() function of Sendmail versions prior to and
including 8.12.9. The sucessful exploitation of this bug can lead to heap
and stack structure overflows. Although no exploit currently exists, this
issue is locally exploitable and may also be remotely exploitable.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2003-0694 to this issue.
Michal Zalewski notified us of this issue Sep16 due to be public Sep23, although
it may have leaked http://hedera.linuxnews.pl/_news/2003/09/17/_long/2170.html
Keeping bug as private until we have confirmation that it is now public
RHSA-2003:284 in progress with security fix
Discussion:
http://marc.theaimsgroup.com/?l=full-disclosure&m=106
Bugzilla
CAN-2003-0694 Sendmail possible remote exploit
bugzilla·2003-09-17
[MEDIUM] CAN-2003-0694 Sendmail possible remote exploit
CAN-2003-0694 Sendmail possible remote exploit
There is a bug in the prescan() function of Sendmail versions prior to and
including 8.12.9. The sucessful exploitation of this bug can lead to heap
and stack structure overflows. Although no exploit currently exists, this
issue is locally exploitable and may also be remotely exploitable.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2003-0694 to this issue.
Michal Zalewski notified us of this issue Sep16 due to be public Sep23, although
it may have leaked http://hedera.linuxnews.pl/_news/2003/09/17/_long/2170.html
Keeping bug as private until we have confirmation that it is now public
RHSA-2003:283 in progress with security fix
Discussion:
Now public
http://marc.theaimsgroup.com/?l=full-discl
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.11/SCOSA-2004.11.txthttp://archives.neohapsis.com/archives/fulldisclosure/2003-q3/4119.htmlhttp://archives.neohapsis.com/archives/vulnwatch/2003-q3/0113.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000742http://marc.info/?l=bugtraq&m=106381604923204&w=2http://marc.info/?l=bugtraq&m=106382859407683&w=2http://marc.info/?l=bugtraq&m=106383437615742&w=2http://marc.info/?l=bugtraq&m=106398718909274&w=2http://www.cert.org/advisories/CA-2003-25.htmlhttp://www.debian.org/security/2003/dsa-384http://www.kb.cert.org/vuls/id/784980http://www.mandriva.com/security/advisories?name=MDKSA-2003:092http://www.redhat.com/support/errata/RHSA-2003-283.htmlhttp://www.redhat.com/support/errata/RHSA-2003-284.htmlhttp://www.sendmail.org/8.12.10.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2975https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A572https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A603ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.11/SCOSA-2004.11.txthttp://archives.neohapsis.com/archives/fulldisclosure/2003-q3/4119.htmlhttp://archives.neohapsis.com/archives/vulnwatch/2003-q3/0113.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000742http://marc.info/?l=bugtraq&m=106381604923204&w=2http://marc.info/?l=bugtraq&m=106382859407683&w=2http://marc.info/?l=bugtraq&m=106383437615742&w=2http://marc.info/?l=bugtraq&m=106398718909274&w=2http://www.cert.org/advisories/CA-2003-25.htmlhttp://www.debian.org/security/2003/dsa-384http://www.kb.cert.org/vuls/id/784980http://www.mandriva.com/security/advisories?name=MDKSA-2003:092http://www.redhat.com/support/errata/RHSA-2003-283.htmlhttp://www.redhat.com/support/errata/RHSA-2003-284.htmlhttp://www.sendmail.org/8.12.10.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2975https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A572https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A603
2003-10-06
Published
Exploited in the wild