Back to Database
Status published
High
CVE-2003-0681
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9,...
Vulnerability Description
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2003-0681
Credits & Attribution
No credits recorded in the NVD database.
References
- http://marc.info/?l=bugtraq&m=106398718909274&w=2
- http://www.sendmail.org/8.12.10.html
- http://www.redhat.com/support/errata/RHSA-2003-283.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A595
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:092
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3606
- http://www.kb.cert.org/vuls/id/108964
- http://www.debian.org/security/2003/dsa-384
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13216
- http://marc.info/?l=bugtraq&m=106383437615742&w=2
- http://www.securityfocus.com/bid/8649
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000742
More from sendmail
View All →CVE-2009-4565
sendmail before 8.14.4 does not properly handle a '\0' character...
High
7.5
CVE-2009-1490
Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers...
Medium
5
CVE-2007-2246
Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail...
High
7.8
CVE-2006-7176
The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux...
Medium
4.3
CVE-2006-7175
The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux...
High
7.5
Affected Vendor
sendmail
View all reports →Affected Software
advanced message server, sendmail, sendmail pro, sendmail switch, mac os x, mac os x server, linux, hp-ux, aix, netbsd, openbsd, turbolinux advanced server, turbolinux server, turbolinux workstation
Vulnerable Versions:
1.2, 1.3, 2.6, 2.6.1, 2.6.2, 3.0, 3.0.1, 3.0.2, 3.0.3, 8.8.8, 8.9.0, 8.9.1, 8.9.2, 8.9.3, 8.10, 8.10.1, 8.10.2, 8.11.0, 8.11.1, 8.11.2, 8.11.3, 8.11.4, 8.11.5, 8.11.6, 8.12, 8.12.0, 8.12.1, 8.12.2, 8.12.3, 8.12.4, 8.12.5, 8.12.6, 8.12.7, 8.12.8, 8.12.9, 2.1, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 2.2, 2.2.1, 2.2.2, 2.2.3, 2.2.4, 2.2.5, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.5, 10.2.6, 0.5, 0.7, 1.1a, 1.4, 11.00, 11.0.4, 11.11, 11.22, 4.3.3, 5.1, 5.2, 1.4.3, 1.5, 1.5.1, 1.5.2, 1.5.3, 1.6, 1.6.1, 3.2, 3.3, 6.0, 6.1, 6.5, 7.0, 8.0
Timeline
Official Publish:
September 18th, 2003
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.