CVE-2003-0688

Sendmail <= 8.12.8 - Denial of Service via Invalid DNS Response

Title source: llm
STIX 2.1

Description

The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.

References (8)

Core 8
Core References
Vendor Advisory vendor-advisory x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2003:086
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A597
Vendor Advisory vendor-advisory x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/20030803-01-P
Various Sources x_refsource_confirm
http://www.sendmail.org/dnsmap1.html
Patch, Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2003-265.html
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2003_035_sendmail.html
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/993452
Vendor Advisory vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000727

Scores

EPSS 0.0171
EPSS Percentile 82.6%

Details

Status published
Products (20)
compaq/tru64 5.0a
compaq/tru64 5.1
freebsd/freebsd 4.6
freebsd/freebsd 4.7
freebsd/freebsd 4.8
freebsd/freebsd 5.0
openbsd/openbsd 3.2
redhat/sendmail 8.12.5-7 (4 CPE variants)
redhat/sendmail 8.12.8-4 (4 CPE variants)
sendmail/sendmail 8.12.1
... and 10 more
Published Oct 20, 2003
Tracked Since Feb 18, 2026