CVE-2003-0161
sendmail-wide - char-to-int conversion
EPSS 38.2%
描述
The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.
如何修補 CVE-2003-0161
要修補 CVE-2003-0161,請將受影響套件升級到下列已修補版本。
- Debian/sendmail—升級至 8.12.9-1 或更新版本
- —升級至 8.12.3-6.3 或更新版本
- —升級至 8.12.3+3.5Wbeta-5.4 或更新版本
CVE-2003-0161 正在被利用嗎?
中等 — EPSS 為 38.2%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 8.12.9-1
- from 0, < 8.12.3-6.3
- from 0, < 8.12.3+3.5Wbeta-5.4