peter bassill · operator
$ cve CVE-2003-0161 JSON

CVE-2003-0161 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 38.8% (pctl 99)

Patch early

A public exploit exists.

Description

The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS38.79% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2003-04-02
Last modified2026-06-16

Affected (9)

VendorProduct
compaqtru64
hphp-ux
hphp-ux series 700
hphp-ux series 800
hpsis
sendmailsendmail
sendmailsendmail switch
sunsolaris
sunsunos

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD