PT-2003-1408 · Sendmail · Sendmail
Michal Zalewski
·
Publicado
2003-04-01
·
Atualizado
2018-10-30
·
CVE-2003-0161
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Sendmail versions prior to 8.12.9
Description:
The issue is related to the
prescan() function in the address parser, which does not properly handle certain conversions from char and int types. This can cause a length check to be disabled when Sendmail misinterprets an input value as a special control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages.Recommendations:
For Sendmail versions prior to 8.12.9, update to version 8.12.9 or later to resolve the issue.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sendmail