CVE-2003-0161

Hp-ux - Buffer Overflow

Title source: rule
STIX 2.1

Description

The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.

Exploits (2)

exploitdb WORKING POC VERIFIED
by bysin · cremotelinux
https://www.exploit-db.com/exploits/24
exploitdb WORKING POC VERIFIED
by sorbo · clocalunix
https://www.exploit-db.com/exploits/22442

References (24)

... and 4 more

Scores

EPSS 0.6790
EPSS Percentile 98.6%

Details

Status published
Products (50)
compaq/tru64 4.0b
compaq/tru64 4.0d
compaq/tru64 4.0d_pk9_bl17
compaq/tru64 4.0f
compaq/tru64 4.0f_pk6_bl17
compaq/tru64 4.0f_pk7_bl18
compaq/tru64 4.0g
compaq/tru64 4.0g_pk3_bl17
compaq/tru64 5.0
compaq/tru64 5.0_pk4_bl17
... and 40 more
Published Apr 02, 2003
Tracked Since Feb 18, 2026