The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T01:43:36.017Z
Reserved: 2003-03-24T00:00:00.000Z
Link: CVE-2003-0161
No data.
Status : Deferred
Published: 2003-04-02T05:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2003-0161
OpenCVE Enrichment
No data.
Weaknesses