CVE-2002-1337
Summary
| CVE | CVE-2002-1337 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-03-07 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-002.txt.asc | af854a3a-2127-422b-91ae-364da2661108 | ftp.netbsd.org | Broken Link |
| 'HP-UX security bulletins digest [Fwd/sendmail issue]' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail | af854a3a-2127-422b-91ae-364da2661108 | www.cert.org | Broken Link, Patch, Third Party Advisory, US Government Resource |
| Search results | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | Broken Link |
| Debian -- Security Information -- DSA-257-1 sendmail | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Broken Link |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| '[LSD] Technical analysis of the remote sendmail vulnerability' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | frontal2.mandriva.com | Broken Link |
| www.iss.net/security_center/static/10748.php | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Broken Link |
| ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.6 | af854a3a-2127-422b-91ae-364da2661108 | ftp.sco.com | Broken Link |
| 'sendmail 8.12.8 available' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| CERT/CC Vulnerability Note VU#398025 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| Home - Conectiva | af854a3a-2127-422b-91ae-364da2661108 | distro.conectiva.com.br | Broken Link |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.5 | af854a3a-2127-422b-91ae-364da2661108 | ftp.sco.com | Broken Link |
| Sendmail - 8.12 | af854a3a-2127-422b-91ae-364da2661108 | www.sendmail.org | Broken Link, Patch, Vendor Advisory |
| Search results | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | Broken Link |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| www.iss.net/issEn/delivery/xforce/alertdetail.jsp | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Broken Link, Patch, Vendor Advisory |
| 'GLSA: sendmail (200303-4)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| patches.sgi.com/support/free/security/advisories/20030301-01-P | af854a3a-2127-422b-91ae-364da2661108 | patches.sgi.com | Broken Link |
| Sendmail Header Processing Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory |
| Search results | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | Broken Link |
| 'Fwd: APPLE-SA-2003-03-03 sendmail' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.