← Back

CVE-2003-0161

nvd nist
Published: Apr 2, 2003Modified: Apr 16, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.

Affected (111)

Show all products
2 products
Sendmail
Sendmail Switch
1 product
Tru64
4 products
Hp Ux
Hp Ux Series 700
Hp Ux Series 800
Sis
2 products
Solaris
Sunos
Configuration A
51 vulnerable
Vulnerable SoftwareAffected Versions
Sendmail
Version 2.6.1
Version 2.6.2
Version 2.6
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.0
Version 8.10.1
Version 8.10.2
Version 8.10
Version 8.11.0
Version 8.11.1
Version 8.11.2
Version 8.11.3
Version 8.11.4
Version 8.11.5
Version 8.11.6
Version 8.12.0
Version 8.12.1
Version 8.12.2
Version 8.12.3
Version 8.12.4
Version 8.12.5
Version 8.12.6
Version 8.12.7
Version 8.12.8
Version 8.12 beta10
Version 8.12 beta12
Version 8.12 beta16
Version 8.12 beta5
Version 8.12 beta7
Version 8.9.0
Version 8.9.1
Version 8.9.2
Version 8.9.3
Sendmail
Version 2.1.1
Version 2.1.2
Version 2.1.3
Version 2.1.4
Version 2.1.5
Version 2.1
Version 2.2.1
Version 2.2.2
Version 2.2.3
Version 2.2.4
Version 2.2.5
Version 2.2
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.0
Configuration B
60 vulnerable
Vulnerable SoftwareAffected Versions
Compaq
Version 4.0b
Version 4.0d
Version 4.0d_pk9_bl17
Version 4.0f
Version 4.0f_pk6_bl17
Version 4.0f_pk7_bl18
Version 4.0g
Version 4.0g_pk3_bl17
Version 5.0
Version 5.0_pk4_bl17
Version 5.0_pk4_bl18
Version 5.0a
Version 5.0a_pk3_bl17
Version 5.0f
Version 5.1
Version 5.1_pk3_bl17
Version 5.1_pk4_bl18
Version 5.1_pk5_bl19
Version 5.1_pk6_bl20
Version 5.1a
Version 5.1a_pk1_bl1
Version 5.1a_pk2_bl2
Version 5.1a_pk3_bl3
Version 5.1b
Version 5.1b_pk1_bl1
Hp
Version 10.00
Version 10.01
Version 10.08
Version 10.09
Version 10.10
Version 10.16
Version 10.20
Version 10.24
Version 10.26
Version 10.30
Version 10.34
Version 11.0.4
Version 11.00
Version 11.11
Version 11.20
Version 11.22
Version 10.20
Version 10.20
All versions
Sun
Version 2.4
Version 2.5.1
Version 2.5.1
Version 2.5
Version 2.6
Version 7.0
Version 8.0
Version 9.0
Version 9.0
Version 9.0 x86_update_2
Sun
All versions
Version 5.4
Version 5.5.1
Version 5.5
Version 5.7
Version 5.8

References (50)

ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-016.0.txt (unsafe URL)
Source: cve@mitre.org
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:07.sendmail.asc (unsafe URL)
Source: cve@mitre.org
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.11/SCOSA-2004.11.txt (unsafe URL)
Source: cve@mitre.org
ftp://patches.sgi.com/support/free/security/advisories/20030401-01-P (unsafe URL)
Source: cve@mitre.org
Source: cve@mitre.org
PatchThird Party AdvisoryUS Government Resource
Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-016.0.txt (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:07.sendmail.asc (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.11/SCOSA-2004.11.txt (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
ftp://patches.sgi.com/support/free/security/advisories/20030401-01-P (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.