CLA-2003:614Vendor advisory
http://distro.conectiva.com.br/atualizacoes?id=a&anuncio=000614 CVE-2003-0161
Sendmail 8.11.6 - Address Prescan Memory Corruption
Record summary
CVE-2003-0161 has a selected CVSS score of 10.0; EIP currently links 2 catalogued exploits.
Description
The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBSendmail 8.11.6 - Address Prescan Memory CorruptionExploitDB exploitby sorboNot analyzed1 file
ExploitDBSendmail 8.12.8 (BSD) - 'Prescan()' Remote Command ExecutionExploitDB exploitby bysinNot analyzed1 file
References
Showing 12 of 21lists.apple.comConfirmation
http://lists.apple.com/mhonarc/security-announce/msg00028.html 20030329 Sendmail: -1 gone wildmailing list
http://lists.grok.org.uk/pipermail/full-disclosure/2003-March/004295.html 20030329 sendmail 8.12.9 availablemailing list
http://marc.info/?l=bugtraq&m=104896621106790&w=2 20030329 Sendmail: -1 gone wildmailing list
http://marc.info/?l=bugtraq&m=104897487512238&w=2 20030330 [OpenPKG-SA-2003.027] OpenPKG Security Advisory (sendmail)mailing list
http://marc.info/?l=bugtraq&m=104914999806315&w=2 52620Vendor advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-52620-1 52700Vendor advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-52700-1 1001088Vendor advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1001088.1-1 CA-2003-12Third-party advisory
http://www.cert.org/advisories/CA-2003-12.html DSA-278Vendor advisory
http://www.debian.org/security/2003/dsa-278 DSA-290Vendor advisory
http://www.debian.org/security/2003/dsa-290