Vulnerability Details CVE-2003-0161
The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.827
EPSS Ranking 99.2%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2003-0161
-
cpe:2.3:a:sendmail:sendmail:2.6
-
cpe:2.3:a:sendmail:sendmail:2.6.1
-
cpe:2.3:a:sendmail:sendmail:2.6.2
-
cpe:2.3:a:sendmail:sendmail:3.0
-
cpe:2.3:a:sendmail:sendmail:3.0.1
-
cpe:2.3:a:sendmail:sendmail:3.0.2
-
cpe:2.3:a:sendmail:sendmail:3.0.3
-
cpe:2.3:a:sendmail:sendmail:8.10
-
cpe:2.3:a:sendmail:sendmail:8.10.1
-
cpe:2.3:a:sendmail:sendmail:8.10.2
-
cpe:2.3:a:sendmail:sendmail:8.11.0
-
cpe:2.3:a:sendmail:sendmail:8.11.1
-
cpe:2.3:a:sendmail:sendmail:8.11.2
-
cpe:2.3:a:sendmail:sendmail:8.11.3
-
cpe:2.3:a:sendmail:sendmail:8.11.4
-
cpe:2.3:a:sendmail:sendmail:8.11.5
-
cpe:2.3:a:sendmail:sendmail:8.11.6
-
cpe:2.3:a:sendmail:sendmail:8.12
-
cpe:2.3:a:sendmail:sendmail:8.12.0
-
cpe:2.3:a:sendmail:sendmail:8.12.1
-
cpe:2.3:a:sendmail:sendmail:8.12.2
-
cpe:2.3:a:sendmail:sendmail:8.12.3
-
cpe:2.3:a:sendmail:sendmail:8.12.4
-
cpe:2.3:a:sendmail:sendmail:8.12.5
-
cpe:2.3:a:sendmail:sendmail:8.12.6
-
cpe:2.3:a:sendmail:sendmail:8.12.7
-
cpe:2.3:a:sendmail:sendmail:8.12.8
-
cpe:2.3:a:sendmail:sendmail:8.9.0
-
cpe:2.3:a:sendmail:sendmail:8.9.1
-
cpe:2.3:a:sendmail:sendmail:8.9.2
-
cpe:2.3:a:sendmail:sendmail:8.9.3
-
cpe:2.3:a:sendmail:sendmail_switch:2.1
-
cpe:2.3:a:sendmail:sendmail_switch:2.1.1
-
cpe:2.3:a:sendmail:sendmail_switch:2.1.2
-
cpe:2.3:a:sendmail:sendmail_switch:2.1.3
-
cpe:2.3:a:sendmail:sendmail_switch:2.1.4
-
cpe:2.3:a:sendmail:sendmail_switch:2.1.5
-
cpe:2.3:a:sendmail:sendmail_switch:2.2
-
cpe:2.3:a:sendmail:sendmail_switch:2.2.1
-
cpe:2.3:a:sendmail:sendmail_switch:2.2.2
-
cpe:2.3:a:sendmail:sendmail_switch:2.2.3
-
cpe:2.3:a:sendmail:sendmail_switch:2.2.4
-
cpe:2.3:a:sendmail:sendmail_switch:2.2.5
-
cpe:2.3:a:sendmail:sendmail_switch:3.0
-
cpe:2.3:a:sendmail:sendmail_switch:3.0.1
-
cpe:2.3:a:sendmail:sendmail_switch:3.0.2
-
cpe:2.3:a:sendmail:sendmail_switch:3.0.3
-
cpe:2.3:o:compaq:tru64:4.0b
-
cpe:2.3:o:compaq:tru64:4.0d
-
cpe:2.3:o:compaq:tru64:4.0d_pk9_bl17
-
cpe:2.3:o:compaq:tru64:4.0f
-
cpe:2.3:o:compaq:tru64:4.0f_pk6_bl17
-
cpe:2.3:o:compaq:tru64:4.0f_pk7_bl18
-
cpe:2.3:o:compaq:tru64:4.0g
-
cpe:2.3:o:compaq:tru64:4.0g_pk3_bl17
-
cpe:2.3:o:compaq:tru64:5.0
-
cpe:2.3:o:compaq:tru64:5.0_pk4_bl17
-
cpe:2.3:o:compaq:tru64:5.0_pk4_bl18
-
cpe:2.3:o:compaq:tru64:5.0a
-
cpe:2.3:o:compaq:tru64:5.0a_pk3_bl17
-
cpe:2.3:o:compaq:tru64:5.0f
-
cpe:2.3:o:compaq:tru64:5.1
-
cpe:2.3:o:compaq:tru64:5.1_pk3_bl17
-
cpe:2.3:o:compaq:tru64:5.1_pk4_bl18
-
cpe:2.3:o:compaq:tru64:5.1_pk5_bl19
-
cpe:2.3:o:compaq:tru64:5.1_pk6_bl20
-
cpe:2.3:o:compaq:tru64:5.1a
-
cpe:2.3:o:compaq:tru64:5.1a_pk1_bl1
-
cpe:2.3:o:compaq:tru64:5.1a_pk2_bl2
-
cpe:2.3:o:compaq:tru64:5.1a_pk3_bl3
-
cpe:2.3:o:compaq:tru64:5.1b
-
cpe:2.3:o:compaq:tru64:5.1b_pk1_bl1
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:o:hp:hp-ux:11.0.4
-
-
-
-
-
cpe:2.3:o:hp:hp-ux_series_700:10.20
-
cpe:2.3:o:hp:hp-ux_series_800:10.20
-
-
cpe:2.3:o:sun:solaris:2.4
-
cpe:2.3:o:sun:solaris:2.5
-
cpe:2.3:o:sun:solaris:2.5.1
-
cpe:2.3:o:sun:solaris:2.6
-
cpe:2.3:o:sun:solaris:7.0
-
cpe:2.3:o:sun:solaris:8.0
-
cpe:2.3:o:sun:solaris:9.0
-
-
-
-
cpe:2.3:o:sun:sunos:5.5.1
-
-