CVE-2002-1337
high · 10Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.
10
CVSS
72.6%
EPSS (exploit prob.)
99th
EPSS percentile
2003-03-07
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-120
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| sendmail | sendmail | < 8.9.3 |
| sendmail | sendmail | >= 8.10.0, < 8.11.6 |
| sendmail | sendmail | >= 8.12.0, < 8.12.8 |
| hp | alphaserver_sc | all versions |
| gentoo | linux | 1.4 |
| gentoo | linux | 1.4 |
| hp | hp-ux | 10.10 |
| hp | hp-ux | 10.20 |
| hp | hp-ux | 11.00 |
| hp | hp-ux | 11.0.4 |
| hp | hp-ux | 11.11 |
| hp | hp-ux | 11.22 |
| netbsd | netbsd | 1.5 |
| netbsd | netbsd | 1.5.1 |
| netbsd | netbsd | 1.5.2 |
| netbsd | netbsd | 1.5.3 |
| netbsd | netbsd | 1.6 |
| oracle | solaris | 2.6 |
| oracle | solaris | 7.0 |
| oracle | solaris | 8 |
| oracle | solaris | 9 |
| sun | sunos | all versions |
| sun | sunos | 5.7 |
| sun | sunos | 5.8 |
| windriver | bsdos | 4.2 |
| windriver | bsdos | 4.3.1 |
| windriver | bsdos | 5.0 |
| windriver | platform_sa | 1.0 |
Check a specific version with /api/v1/cve/match.
References
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-002.txt.asc
- ftp://ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.6
- ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.5
- ftp://patches.sgi.com/support/free/security/advisories/20030301-01-P
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000571
- http://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:028
- http://marc.info/?l=bugtraq&m=104673778105192&w=2
- http://marc.info/?l=bugtraq&m=104678739608479&w=2
- http://marc.info/?l=bugtraq&m=104678862109841&w=2
- http://marc.info/?l=bugtraq&m=104678862409849&w=2
- http://marc.info/?l=bugtraq&m=104679411316818&w=2
- http://www-1.ibm.com/support/search.wss?rs=0&q=IY40500&apar=only
- http://www-1.ibm.com/support/search.wss?rs=0&q=IY40501&apar=only
- http://www-1.ibm.com/support/search.wss?rs=0&q=IY40502&apar=only
- http://www.cert.org/advisories/CA-2003-07.html
- http://www.debian.org/security/2003/dsa-257
- http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21950
- http://www.iss.net/security_center/static/10748.php
- http://www.kb.cert.org/vuls/id/398025
- http://www.redhat.com/support/errata/RHSA-2003-073.html
- http://www.redhat.com/support/errata/RHSA-2003-074.html
- http://www.redhat.com/support/errata/RHSA-2003-227.html
- http://www.securityfocus.com/bid/6991
- http://www.sendmail.org/8.12.8.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2222
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2002-1337