Lucene search

K
cve[email protected]CVE-2003-0688
HistoryOct 20, 2003 - 4:00 a.m.

CVE-2003-0688

2003-10-2004:00:00
web.nvd.nist.gov
22
sendmail
dns
vulnerability
denial of service
remote attackers

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.7 Medium

AI Score

Confidence

High

0.129 Low

EPSS

Percentile

95.5%

The DNS map code in Sendmail 8.12.8 and earlier, when using the “enhdnsbl” feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.

Affected configurations

NVD
Node
redhatsendmailMatch8.12.5-7i386
OR
redhatsendmailMatch8.12.5-7i386_cf
OR
redhatsendmailMatch8.12.5-7i386_dev
OR
redhatsendmailMatch8.12.5-7i386_doc
OR
redhatsendmailMatch8.12.8-4i386
OR
redhatsendmailMatch8.12.8-4i386_cf
OR
redhatsendmailMatch8.12.8-4i386_dev
OR
redhatsendmailMatch8.12.8-4i386_doc
OR
sendmailsendmailMatch8.12.1
OR
sendmailsendmailMatch8.12.2
OR
sendmailsendmailMatch8.12.3
OR
sendmailsendmailMatch8.12.4
OR
sendmailsendmailMatch8.12.5
OR
sendmailsendmailMatch8.12.6
OR
sendmailsendmailMatch8.12.7
OR
sendmailsendmailMatch8.12.8
OR
sgiirixMatch6.5.19
OR
sgiirixMatch6.5.20
OR
sgiirixMatch6.5.21
Node
compaqtru64Match5.0a
OR
compaqtru64Match5.1
OR
freebsdfreebsdMatch4.6
OR
freebsdfreebsdMatch4.7
OR
freebsdfreebsdMatch4.8
OR
freebsdfreebsdMatch5.0
OR
openbsdopenbsdMatch3.2

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.7 Medium

AI Score

Confidence

High

0.129 Low

EPSS

Percentile

95.5%