CVE-2003-0688: Medium severity redhat Sendmail vulnerability
The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0688?
CVE-2003-0688 has been classified as critical due to its potential to cause denial of service by crashing the Sendmail process.
How do I fix CVE-2003-0688?
To fix CVE-2003-0688, update Sendmail to version 8.12.9 or later, which addresses this vulnerability.
Which versions of Sendmail are affected by CVE-2003-0688?
CVE-2003-0688 affects Sendmail versions 8.12.8 and earlier.
What type of attack does CVE-2003-0688 enable?
CVE-2003-0688 enables remote attackers to cause Sendmail to crash, resulting in a denial of service.
Is CVE-2003-0688 related to DNS responses?
Yes, CVE-2003-0688 is triggered by invalid DNS responses due to improper initialization in the DNS map code.