VulnerabilityModified
CVE-2002-1337
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.
HIGH 10.0EPSS 72.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 72.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 72.64% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- sendmail/sendmail · hp/alphaserver sc · gentoo/linux · hp/hp-ux · netbsd/netbsd · oracle/solaris · sun/sunos · windriver/bsdos · windriver/platform sa
- Source
- cve@mitre.org
References
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-002.txt.ascBroken Link
- ftp://ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.6Broken Link
- ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.5Broken Link
- ftp://patches.sgi.com/support/free/security/advisories/20030301-01-PBroken Link
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000571Broken Link
- http://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:028Broken Link
- http://marc.info/?l=bugtraq&m=104673778105192&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=104678739608479&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=104678862109841&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=104678862409849&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=104679411316818&w=2Third Party Advisory
- http://www-1.ibm.com/support/search.wss?rs=0&q=IY40500&apar=onlyBroken Link
- http://www-1.ibm.com/support/search.wss?rs=0&q=IY40501&apar=onlyBroken Link
- http://www-1.ibm.com/support/search.wss?rs=0&q=IY40502&apar=onlyBroken Link
- http://www.cert.org/advisories/CA-2003-07.htmlBroken Link, Patch, Third Party Advisory, US Government Resource
- http://www.debian.org/security/2003/dsa-257Broken Link
- http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21950Broken Link, Patch, Vendor Advisory
- http://www.iss.net/security_center/static/10748.phpBroken Link
- http://www.kb.cert.org/vuls/id/398025Third Party Advisory, US Government Resource
- http://www.redhat.com/support/errata/RHSA-2003-073.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2003-074.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2003-227.htmlBroken Link
- http://www.securityfocus.com/bid/6991Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.sendmail.org/8.12.8.htmlBroken Link, Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2222Broken Link
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-002.txt.ascBroken Link
- ftp://ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.6Broken Link
- ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.5Broken Link
- ftp://patches.sgi.com/support/free/security/advisories/20030301-01-PBroken Link
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000571Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.