Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux

CVE-2003-0681
CVE information
Published
Last Modified
CVSSv2.0 Severity
Impact Analysis
Description
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences..
CVSSv2.0 Score
- Severity
- High
- Base Score
- 7.5/10
- Exploit Score
- 10/10
- Access Vector
- Network
- Access Complexity
- Low
- Authentication Required
- None
- Impact Score
- 6.4/10
- Confidentiality Impact
- Partial
- Availability Impact
- Partial
- Integrity Impact
- Partial
Products Affected
CPE | Affected | Vulnerable | Excluding | Edit |
---|---|---|---|---|
cpe:2.3:a:sendmail:sendmail_switch:2.1.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail_switch:3.0.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail_switch:2.2.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:2.6.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.9.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail_switch:2.1.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.11.4:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.8.8:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.12:beta16:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:advanced_message_server:1.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:advanced_message_server:1.3:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.11.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.12.3:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.12:beta12:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail_pro:8.9.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail_switch:2.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.11.3:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.12.4:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail_switch:2.2.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:2.6:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:2.6.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.10.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.11.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.12.8:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.12.9:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.9.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail_switch:2.1.3:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.10:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.10.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.11.5:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.11.6:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.12.6:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.12.7:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.9.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail_switch:2.2.3:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail_switch:2.2.4:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:3.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:3.0.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.11.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.12.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.12:beta10:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.9.3:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail_switch:2.1.5:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail_switch:3.0.3:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:3.0.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:3.0.3:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.12.5:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.12:beta5:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.12:beta7:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail_pro:8.9.3:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail_switch:2.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.12.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail:8.12.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail_switch:2.1.4:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail_switch:2.2.5:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail_switch:3.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:sendmail:sendmail_switch:3.0.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:turbolinux:turbolinux_server:6.5:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:netbsd:netbsd:1.5.3:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:netbsd:netbsd:1.6:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:apple:mac_os_x:10.2.5:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:hp:hp-ux:11.11:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:apple:mac_os_x_server:10.2.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:apple:mac_os_x_server:10.2.4:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:netbsd:netbsd:1.5:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:apple:mac_os_x:10.2.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:apple:mac_os_x:10.2.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:apple:mac_os_x_server:10.2.3:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:gentoo:linux:1.4:rc1:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:ibm:aix:5.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:turbolinux:turbolinux_server:7.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:gentoo:linux:0.5:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:hp:hp-ux:11.00:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:netbsd:netbsd:1.5.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:openbsd:openbsd:3.3:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:netbsd:netbsd:1.5:*:sh3:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:apple:mac_os_x:10.2.4:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:apple:mac_os_x_server:10.2.5:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:gentoo:linux:1.4:rc3:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:hp:hp-ux:11.0.4:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:netbsd:netbsd:1.6.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:netbsd:netbsd:1.6:beta:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:turbolinux:turbolinux_workstation:6.0:*:*:*:*:*:*: |
Yes
|
- | - | |
cpe:2.3:o:turbolinux:turbolinux_workstation:7.0:*:*:*:*:*:*: |
Yes
|
- | - | |
cpe:2.3:o:gentoo:linux:1.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:gentoo:linux:1.4:rc2:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:ibm:aix:5.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:netbsd:netbsd:1.5:*:x86:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:turbolinux:turbolinux_server:8.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:apple:mac_os_x:10.2.6:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:apple:mac_os_x_server:10.2.6:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:netbsd:netbsd:1.5.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:openbsd:openbsd:3.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:turbolinux:turbolinux_workstation:8.0:*:*:*:*:*:*: |
Yes
|
- | - | |
cpe:2.3:o:apple:mac_os_x:10.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:apple:mac_os_x_server:10.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:apple:mac_os_x_server:10.2.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:gentoo:linux:0.7:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:gentoo:linux:1.1a:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:hp:hp-ux:11.22:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:ibm:aix:4.3.3:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:turbolinux:turbolinux_advanced_server:6.0:*:*:*:*: |
Yes
|
- | - | |
cpe:2.3:o:turbolinux:turbolinux_server:6.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:apple:mac_os_x:10.2.3:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:netbsd:netbsd:1.4.3:*:*:*:*:*:*:* |
Yes
|
- | - |
References
- http://www.sendmail.org/8.12.10.html
- http://www.securityfocus.com/bid/8649
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000742
- http://www.debian.org/security/2003/dsa-384
- http://www.redhat.com/support/errata/RHSA-2003-283.html
- http://www.kb.cert.org/vuls/id/108964
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:092
- http://marc.info/?l=bugtraq&m=106383437615742&w=2
- http://marc.info/?l=bugtraq&m=106398718909274&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13216
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3