Description
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.
Affected products
- gentoo / linux1.4 β 1.4
- gentoo / linux1.4 β 1.4
- HP / alphaserver_sc
- HP / hp-ux11.00 β 11.00
- HP / hp-ux11.0.4 β 11.0.4
- HP / hp-ux11.22 β 11.22
- HP / hp-ux11.11 β 11.11
- HP / hp-ux10.10 β 10.10
- HP / hp-ux10.20 β 10.20
- NetBSD / netbsd1.5.3 β 1.5.3
- NetBSD / netbsd1.5 β 1.5
- NetBSD / netbsd1.5.1 β 1.5.1
- NetBSD / netbsd1.5.2 β 1.5.2
- NetBSD / netbsd1.6 β 1.6
- oracle / solaris8 β 8
- oracle / solaris2.6 β 2.6
- oracle / solaris7.0 β 7.0
- oracle / solaris9 β 9
- sendmail / sendmail8.9.3
- sun / sunos
- sun / sunos5.7 β 5.7
- sun / sunos5.8 β 5.8
- windriver / bsdos4.2 β 4.2
- windriver / bsdos4.3.1 β 4.3.1
- windriver / bsdos5.0 β 5.0
- windriver / platform_sa1.0 β 1.0
References
- MISChttp://www.redhat.com/support/errata/RHSA-2003-073.html
- VENDOR_ADVISORYftp://patches.sgi.com/support/free/security/advisories/20030301-01-P
- MISChttp://www-1.ibm.com/support/search.wss?rs=0&q=IY40501&apar=only
- MAILING_LISThttp://marc.info/?l=bugtraq&m=104678862109841&w=2
- MISChttp://www.redhat.com/support/errata/RHSA-2003-227.html
- MISChttp://www.securityfocus.com/bid/6991
- MISChttp://www.kb.cert.org/vuls/id/398025
- MISChttp://www.sendmail.org/8.12.8.html
- VENDOR_ADVISORYhttp://www.debian.org/security/2003/dsa-257
- MAILING_LISThttp://marc.info/?l=bugtraq&m=104678739608479&w=2
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2222
- MISChttp://www.redhat.com/support/errata/RHSA-2003-074.html
- VENDOR_ADVISORYhttp://www.cert.org/advisories/CA-2003-07.html
- MAILING_LISThttp://marc.info/?l=bugtraq&m=104673778105192&w=2
- VENDOR_ADVISORYhttp://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:028
- MISChttp://www-1.ibm.com/support/search.wss?rs=0&q=IY40500&apar=only
- MISChttp://www.iss.net/security_center/static/10748.php
- MISCftp://ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.6
- MISCftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.5
- MISChttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000571
- VENDOR_ADVISORYftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-002.txt.asc
- MAILING_LISThttp://marc.info/?l=bugtraq&m=104679411316818&w=2
- MISChttp://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21950
- MISChttp://www-1.ibm.com/support/search.wss?rs=0&q=IY40502&apar=only
- MAILING_LISThttp://marc.info/?l=bugtraq&m=104678862409849&w=2