SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2003-0694

The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.

HIGH 10.0EPSS 66.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 66.2%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
66.18% probability · 99th percentile
CISA KEV
Not listed
Affected
sendmail/advanced message server · sendmail/sendmail · sendmail/sendmail pro · sendmail/sendmail switch · sgi/irix · apple/mac os x · apple/mac os x server · compaq/tru64 · freebsd/freebsd · gentoo/linux · hp/hp-ux · ibm/aix · netbsd/netbsd · sun/solaris · sun/sunos · turbolinux/turbolinux advanced server · turbolinux/turbolinux server · turbolinux/turbolinux workstation
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.