Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.
References
Link Providers
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-002.txt.asc cve-icon cve-icon
ftp://ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.6 cve-icon cve-icon
ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.5 cve-icon cve-icon
ftp://patches.sgi.com/support/free/security/advisories/20030301-01-P cve-icon cve-icon
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000571 cve-icon cve-icon
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:028 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=104673778105192&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=104678739608479&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=104678862109841&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=104678862409849&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=104679411316818&w=2 cve-icon cve-icon
http://www-1.ibm.com/support/search.wss?rs=0&q=IY40500&apar=only cve-icon cve-icon
http://www-1.ibm.com/support/search.wss?rs=0&q=IY40501&apar=only cve-icon cve-icon
http://www-1.ibm.com/support/search.wss?rs=0&q=IY40502&apar=only cve-icon cve-icon
http://www.cert.org/advisories/CA-2003-07.html cve-icon cve-icon
http://www.debian.org/security/2003/dsa-257 cve-icon cve-icon
http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21950 cve-icon cve-icon
http://www.iss.net/security_center/static/10748.php cve-icon cve-icon
http://www.kb.cert.org/vuls/id/398025 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2003-073.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2003-074.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2003-227.html cve-icon cve-icon
http://www.securityfocus.com/bid/6991 cve-icon cve-icon
http://www.sendmail.org/8.12.8.html cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2002-1337 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2222 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2002-1337 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2004-09-01T04:00:00

Updated: 2024-08-08T03:19:28.722Z

Reserved: 2002-12-03T00:00:00

Link: CVE-2002-1337

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2003-03-07T05:00:00.000

Modified: 2024-02-09T03:19:11.660

Link: CVE-2002-1337

cve-icon Redhat

Severity : Critical

Publid Date: 2003-03-03T00:00:00Z

Links: CVE-2002-1337 - Bugzilla