CVE-2003-0308: High severity Sendmail Sendmail vulnerability
Published May 15, 2003
·Updated
The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privileges via (1) expn, (2) checksendmail, or (3) doublebounce.pl.
Affected Software
4 affected components
Sendmail Sendmail=8.12.3
Sendmail Sendmail=8.12.9
Sendmail Sendmail=8.9.3
Debian Debian Linux=3.0
Remediation
Patch Available
Event History
May 15, 2003
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
May 17, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-0308?
CVE-2003-0308 is classified as a high-severity vulnerability due to the potential for local privilege escalation.
2
How do I fix CVE-2003-0308?
To fix CVE-2003-0308, users should upgrade to a patched version of Sendmail that securely creates temporary files.
3
Which versions of Sendmail are impacted by CVE-2003-0308?
CVE-2003-0308 affects Sendmail versions 8.12.3, 8.12.9, and 8.9.3 on Debian GNU/Linux 3.0.
4
Can CVE-2003-0308 be exploited remotely?
CVE-2003-0308 cannot be exploited remotely, as it requires local access to the system.
5
What are the attack vectors for CVE-2003-0308?
The attack vectors for CVE-2003-0308 include using expn, checksendmail, or doublebounce.pl to gain additional privileges.