CVE-2003-0694: Buffer Overflow
Published Sep 18, 2003
·Updated
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
Affected Software
163 affected components
Sendmail Sendmail Switch=2.1.2
Sendmail Sendmail Switch=3.0.2
Sendmail Sendmail Switch=2.2.2
Sendmail Sendmail=2.6.2
Sendmail Sendmail=8.9.2
Sendmail Sendmail Switch=2.1.1
Sendmail Sendmail=8.11.4
Sendmail Sendmail=8.8.8
Sendmail Sendmail=8.12-beta16
Sendmail Advanced Message Server=1.3
Sendmail Sendmail=2.6
Sendmail Sendmail=8.11.1
Sendmail Sendmail=8.12.3
Sendmail Sendmail=8.11.3
Sendmail Sendmail=8.12.8
SGI IRIX=6.5.17f
SGI IRIX=6.5.21f
SGI IRIX=6.5.21m
Sendmail Sendmail Pro=8.9.2
Sendmail Sendmail Switch=2.2.1
SGI IRIX=6.5.19f
Sendmail Sendmail=2.6.1
Sendmail Sendmail=8.11.0
Sendmail Sendmail=8.12.9
Sendmail Sendmail=8.9.1
Sendmail Sendmail Switch=2.1.3
SGI IRIX=6.5.18f
Sendmail Sendmail=8.10
Sendmail Sendmail=8.10.1
Sendmail Sendmail=8.11.6
Sendmail Sendmail=8.12.7
Sendmail Sendmail=3.0
Sendmail Sendmail=3.0.1
Sendmail Sendmail=8.11.2
Sendmail Sendmail=8.12.2
Sendmail Sendmail=8.12-beta12
Sendmail Sendmail=8.9.3
Sendmail Advanced Message Server=1.2
Sendmail Sendmail=3.0.2
Sendmail Sendmail=3.0.3
Sendmail Sendmail=8.12.4
Sendmail Sendmail=8.12.5
Sendmail Sendmail=8.12.6
Sendmail Sendmail=8.12-beta5
Sendmail Sendmail=8.12-beta7
Sendmail Sendmail Pro=8.9.3
Sendmail Sendmail Switch=2.1
Sendmail Sendmail Switch=2.2.3
SGI IRIX=6.5.15
SGI IRIX=6.5.20f
SGI IRIX=6.5.20m
Sendmail Sendmail=8.9.0
Sendmail Sendmail Switch=2.2.5
SGI IRIX=6.5.17m
Sendmail Sendmail Switch=2.1.5
Sendmail Sendmail Switch=2.2
SGI IRIX=6.5.19m
Sendmail Sendmail=8.10.2
Sendmail Sendmail=8.12.0
Sendmail Sendmail=8.12.1
Sendmail Sendmail=8.12-beta10
Sendmail Sendmail Switch=3.0
Sendmail Sendmail Switch=3.0.1
Sendmail Sendmail=8.11.5
SGI IRIX=6.5.16
Sendmail Sendmail Switch=2.2.4
Sendmail Sendmail Switch=3.0.3
Sendmail Sendmail Switch=2.1.4
SGI IRIX=6.5.18m
FreeBSD FreeBSD=4.3-releng
Turbolinux Turbolinux Server=6.5
NetBSD NetBSD=1.5.3
FreeBSD FreeBSD=4.6-releng
NetBSD NetBSD=1.6
Apple iOS and macOS=10.2.5
FreeBSD FreeBSD=3.0-releng
HP HP-UX=11.11
Compaq Tru64=5.1_pk3_bl17
FreeBSD FreeBSD=4.3-release_p38
Sun SunOS=5.7
Compaq Tru64=5.1_pk4_bl18
FreeBSD FreeBSD=4.8-release_p6
Turbolinux Turbolinux Server=7.0
Apple Mac OS X Server=10.2.3
Apple Mac OS X Server=10.2.4
FreeBSD FreeBSD=4.6-release_p20
FreeBSD FreeBSD=5.1-release_p5
FreeBSD FreeBSD=5.1-releng
NetBSD NetBSD=1.5
Apple iOS and macOS=10.2.1
Apple Mac OS X Server=10.2.2
Compaq Tru64=5.1b_pk1_bl1
FreeBSD FreeBSD=5.0-release_p14
FreeBSD FreeBSD=5.0-releng
NetBSD NetBSD=1.6.1
Turbolinux Turbolinux Workstation=6.0
Apple iOS and macOS=10.2.4
Apple Mac OS X Server=10.2.5
Compaq Tru64=5.1a_pk3_bl3
Compaq Tru64=5.1a_pk4_bl21
FreeBSD FreeBSD=4.7-release_p17
FreeBSD FreeBSD=4.7-releng
Gentoo Linux=0.5
HP HP-UX=11.00
NetBSD NetBSD=1.5.1
NetBSD NetBSD=1.5.2
Compaq Tru64=4.0f
Compaq Tru64=4.0f_pk6_bl17
Compaq Tru64=5.1_pk5_bl19
FreeBSD FreeBSD=4.4-release_p42
FreeBSD FreeBSD=4.4-releng
FreeBSD FreeBSD=4.9-pre-release
Gentoo Linux=1.1a
HP HP-UX=11.22
IBM AIX=4.3.3
NetBSD NetBSD=1.5
NetBSD NetBSD=1.5
Sun Solaris=7.0
Sun SunOS=5.8
Apple iOS and macOS=10.2.2
Compaq Tru64=4.0g
Compaq Tru64=4.0g_pk3_bl17
Gentoo Linux=1.4-rc3
HP HP-UX=11.0.4
NetBSD NetBSD=1.6-beta
Sun Solaris=9.0
Compaq Tru64=4.0f_pk8_bl22
Compaq Tru64=5.1_pk6_bl20
FreeBSD FreeBSD=4.5-release_p32
Gentoo Linux=1.4-rc1
IBM AIX=5.2
Turbolinux Turbolinux Workstation=7.0
Apple Mac OS X Server=10.2.6
Compaq Tru64=4.0g_pk4_bl22
Compaq Tru64=5.1
Gentoo Linux=0.7
Sun SunOS
Turbolinux Turbolinux Server=6.1
Apple iOS and macOS=10.2.6
Apple Mac OS X Server=10.2
Compaq Tru64=5.1a_pk5_bl23
Compaq Tru64=5.1b
FreeBSD FreeBSD=4.8-releng
Gentoo Linux=1.2
Turbolinux Turbolinux Server=8.0
Apple iOS and macOS=10.2.3
Compaq Tru64=5.1a_pk1_bl1
Compaq Tru64=5.1a_pk2_bl2
FreeBSD FreeBSD=4.0-releng
NetBSD NetBSD=1.4.3
Sun Solaris=2.6
Turbolinux Turbolinux Advanced Server=6.0
Turbolinux Turbolinux Workstation=8.0
Apple iOS and macOS=10.2
Apple Mac OS X Server=10.2.1
Compaq Tru64=4.0f_pk7_bl18
Compaq Tru64=5.1a
Compaq Tru64=5.1b_pk2_bl22
FreeBSD FreeBSD=4.5-releng
Gentoo Linux=1.4-rc2
IBM AIX=5.1
Sun Solaris=8.0
Sun Solaris=9.0
Remediation
Patch Available
Patch Available
Event History
Sep 18, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Oct 6, 2003
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0694?
CVE-2003-0694 has a high severity due to the potential for remote code execution via buffer overflow.
2
How do I fix CVE-2003-0694?
To fix CVE-2003-0694, update Sendmail to version 8.12.10 or later, which addresses the buffer overflow vulnerability.
3
What versions of Sendmail are affected by CVE-2003-0694?
CVE-2003-0694 affects Sendmail versions 8.12.9 and earlier, as well as various Sendmail Switch versions.
4
What kind of attacks can exploit CVE-2003-0694?
CVE-2003-0694 can be exploited through specially crafted email messages that trigger the buffer overflow.
5
Is CVE-2003-0694 specific to certain operating systems?
CVE-2003-0694 is not limited to specific operating systems, as the affected Sendmail versions run on multiple platforms.