VulnerabilityModified
CVE-2003-0694
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
HIGH 10.0EPSS 66.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 66.2%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 66.18% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- sendmail/advanced message server · sendmail/sendmail · sendmail/sendmail pro · sendmail/sendmail switch · sgi/irix · apple/mac os x · apple/mac os x server · compaq/tru64 · freebsd/freebsd · gentoo/linux · hp/hp-ux · ibm/aix · netbsd/netbsd · sun/solaris · sun/sunos · turbolinux/turbolinux advanced server · turbolinux/turbolinux server · turbolinux/turbolinux workstation
- Source
- cve@mitre.org
References
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.11/SCOSA-2004.11.txt
- http://archives.neohapsis.com/archives/fulldisclosure/2003-q3/4119.html
- http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0113.html
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000742
- http://marc.info/?l=bugtraq&m=106381604923204&w=2
- http://marc.info/?l=bugtraq&m=106382859407683&w=2
- http://marc.info/?l=bugtraq&m=106383437615742&w=2
- http://marc.info/?l=bugtraq&m=106398718909274&w=2
- http://www.cert.org/advisories/CA-2003-25.htmlPatch, Third Party Advisory, US Government Resource
- http://www.debian.org/security/2003/dsa-384
- http://www.kb.cert.org/vuls/id/784980US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:092
- http://www.redhat.com/support/errata/RHSA-2003-283.html
- http://www.redhat.com/support/errata/RHSA-2003-284.html
- http://www.sendmail.org/8.12.10.htmlPatch
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2975
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A572
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A603
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.11/SCOSA-2004.11.txt
- http://archives.neohapsis.com/archives/fulldisclosure/2003-q3/4119.html
- http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0113.html
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000742
- http://marc.info/?l=bugtraq&m=106381604923204&w=2
- http://marc.info/?l=bugtraq&m=106382859407683&w=2
- http://marc.info/?l=bugtraq&m=106383437615742&w=2
- http://marc.info/?l=bugtraq&m=106398718909274&w=2
- http://www.cert.org/advisories/CA-2003-25.htmlPatch, Third Party Advisory, US Government Resource
- http://www.debian.org/security/2003/dsa-384
- http://www.kb.cert.org/vuls/id/784980US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:092
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.