cbcvebase.
CVE-2003-0694
published 2003-10-06

CVE-2003-0694: The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr…

PriorityP269critical10CVSS 2.0
AVNACLAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
60.19%
99.0th percentile
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.

Affected

149 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x_server
applemac_os_x_server
applemac_os_x_server
applemac_os_x_server
applemac_os_x_server
applemac_os_x_server
applemac_os_x_server
compaqtru64
compaqtru64
compaqtru64
compaqtru64
compaqtru64
compaqtru64
compaqtru64
compaqtru64
compaqtru64
compaqtru64
compaqtru64

Detection & IOCsextracted from sources · hover to see the quote

versionSendmail 8.12.9
versionSendmail 8.12.8 and earlier
  • Monitor SMTP header parsing in Sendmail for buffer overflow attempts targeting the prescan() function, particularly malformed address fields processed by parseaddr.c.
  • Inspect inbound SMTP traffic for address fields containing 0x5c (backslash) and 0x00 (null) byte sequences, which are the constrained byte values usable in exploitation of this vulnerability.
  • ·Exploitation is constrained to only 0x5c and 0x00 bytes within the prescan function, significantly limiting the ability to achieve arbitrary code execution (more likely a DoS/memory corruption outcome).
  • ·The Metasploit module for this CVE is classified as auxiliary/dos (denial of service), not a full remote code execution exploit, reflecting the byte constraint limitation.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vulncheck10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.