Sendmail Prescan() Variant Remote Buffer Overrun Vulnerability

BID:8641

Info

Sendmail Prescan() Variant Remote Buffer Overrun Vulnerability

Bugtraq ID: 8641
Class: Boundary Condition Error
CVE: CVE-2003-0694
Remote: Yes
Local: Yes
Published: Sep 17 2003 12:00AM
Updated: Jul 11 2009 11:56PM
Credit: Discovery is credited to Michal Zalewski <[email protected]>.
Vulnerable: Turbolinux Turbolinux Workstation 8.0
Turbolinux Turbolinux Workstation 7.0
Turbolinux Turbolinux Workstation 6.0
Turbolinux Turbolinux Server 8.0
Turbolinux Turbolinux Server 7.0
Turbolinux Turbolinux Server 6.5
Turbolinux Turbolinux Server 6.1
Turbolinux Turbolinux Advanced Server 6.0
Sun Solaris 9_x86
Sun Solaris 9
Sun Solaris 8_x86
Sun Solaris 8_sparc
Sun Solaris 7.0_x86
Sun Solaris 7.0
Sun Solaris 2.6_x86
Sun Solaris 2.6
Sun Linux 5.0.7
Sun Cobalt RaQ 550
Sun Cobalt RaQ 4
SGI IRIX 6.5.21 m
SGI IRIX 6.5.21 f
SGI IRIX 6.5.20 m
SGI IRIX 6.5.20 f
SGI IRIX 6.5.19 m
SGI IRIX 6.5.19 f
SGI IRIX 6.5.18 m
SGI IRIX 6.5.18 f
SGI IRIX 6.5.17 m
SGI IRIX 6.5.17 f
SGI IRIX 6.5.16
SGI IRIX 6.5.15
Sendmail, Inc Sendmail for NT 3.0.3
Sendmail, Inc Sendmail for NT 3.0.2
Sendmail, Inc Sendmail for NT 3.0.1
Sendmail, Inc Sendmail for NT 3.0
Sendmail, Inc Sendmail for NT 2.6.2
Sendmail, Inc Sendmail for NT 2.6.1
Sendmail, Inc Sendmail for NT 2.6
Sendmail Inc Sendmail Switch 3.0.3
Sendmail Inc Sendmail Switch 3.0.2
Sendmail Inc Sendmail Switch 3.0.1
Sendmail Inc Sendmail Switch 3.0
Sendmail Inc Sendmail Switch 2.2.5
Sendmail Inc Sendmail Switch 2.2.4
Sendmail Inc Sendmail Switch 2.2.3
Sendmail Inc Sendmail Switch 2.2.2
Sendmail Inc Sendmail Switch 2.2.1
Sendmail Inc Sendmail Switch 2.2
Sendmail Inc Sendmail Switch 2.1.5
Sendmail Inc Sendmail Switch 2.1.4
Sendmail Inc Sendmail Switch 2.1.3
Sendmail Inc Sendmail Switch 2.1.2
Sendmail Inc Sendmail Switch 2.1.1
Sendmail Inc Sendmail Switch 2.1
Sendmail Inc Sendmail Pro 8.9.3
Sendmail Inc Sendmail Pro 8.9.2
Sendmail Inc Sendmail Advanced Message Server 1.3
Sendmail Inc Sendmail Advanced Message Server 1.2
Sendmail Consortium Sendmail 8.12.9
Sendmail Consortium Sendmail 8.12.8
+ Redhat Linux 9.0 i386
+ Redhat Linux 8.0 i386
+ Yellow Dog Linux 3.0
Sendmail Consortium Sendmail 8.12.7
+ OpenPKG OpenPKG 1.2
+ Slackware Linux 8.1
+ SOTLinux SOTLinux 2003 Desktop
+ SOTLinux SOTLinux 2003 Server
Sendmail Consortium Sendmail 8.12.6
Sendmail Consortium Sendmail 8.12.5
Sendmail Consortium Sendmail 8.12.4
Sendmail Consortium Sendmail 8.12.3
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ FreeBSD FreeBSD 4.6
+ SuSE Linux 8.0 i386
+ SuSE Linux 8.0
Sendmail Consortium Sendmail 8.12.2
Sendmail Consortium Sendmail 8.12.1
+ HP MPE/iX 7.5
+ HP MPE/iX 7.0
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2
Sendmail Consortium Sendmail 8.12 beta7
Sendmail Consortium Sendmail 8.12 beta5
Sendmail Consortium Sendmail 8.12 beta16
Sendmail Consortium Sendmail 8.12 beta12
Sendmail Consortium Sendmail 8.12 beta10
Sendmail Consortium Sendmail 8.12 .0
Sendmail Consortium Sendmail 8.11.6
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Workstation 3.1.1
+ Caldera OpenLinux Workstation 3.1
+ FreeBSD FreeBSD 4.5 -RELEASE
+ FreeBSD FreeBSD 4.5
+ FreeBSD FreeBSD 4.4
+ Immunix Immunix OS 7.0
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1
+ Mandriva Linux Mandrake 8.0 ppc
+ Mandriva Linux Mandrake 8.0
+ Redhat Linux 7.3 i386
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.1 i386
+ Redhat Linux 7.0 i386
+ Redhat Linux 6.2 i386
+ Sun Cobalt RaQ 550
+ Sun Linux 5.0.3
+ Sun Linux 5.0
+ SuSE Linux 7.3 sparc
+ SuSE Linux 7.3 ppc
+ SuSE Linux 7.3 i386
+ SuSE Linux 7.3
Sendmail Consortium Sendmail 8.11.5
Sendmail Consortium Sendmail 8.11.4
- Slackware Linux 8.0
Sendmail Consortium Sendmail 8.11.3
- MandrakeSoft Corporate Server 1.0.1
- Mandriva Linux Mandrake 8.0
- Slackware Linux 7.1
+ SuSE Linux 7.2 i386
+ SuSE Linux 7.2
Sendmail Consortium Sendmail 8.11.2
+ Redhat Linux 7.1 ia64
+ Redhat Linux 7.1 i386
+ Redhat Linux 7.1 alpha
+ Redhat Linux 7.1
+ SuSE Linux 7.1 x86
+ SuSE Linux 7.1 sparc
+ SuSE Linux 7.1 ppc
+ SuSE Linux 7.1 alpha
+ SuSE Linux 7.1
Sendmail Consortium Sendmail 8.11.1
Sendmail Consortium Sendmail 8.11
+ Compaq Tru64 5.1 b
+ Compaq Tru64 5.1 a
+ Compaq Tru64 5.1
+ IBM AIX 5.2
+ IBM AIX 5.1
- Mandriva Linux Mandrake 7.2
+ Redhat Linux 7.0 sparc
+ Redhat Linux 7.0 i386
+ Redhat Linux 7.0 alpha
+ Redhat Linux 7.0
+ SCO Open Server 5.0.6 a
+ SCO Open Server 5.0.6
+ SCO Open Server 5.0.5
+ SCO Open Server 5.0.4
- SuSE Linux 7.0 sparc
- SuSE Linux 7.0 ppc
- SuSE Linux 7.0 alpha
- SuSE Linux 7.0
Sendmail Consortium Sendmail 8.10.2
Sendmail Consortium Sendmail 8.10.1
Sendmail Consortium Sendmail 8.10
Sendmail Consortium Sendmail 8.9.3
+ Compaq Tru64 5.1 PK5 (BL19)
+ Compaq Tru64 5.0 a PK3 (BL17)
+ Debian Linux 2.2 sparc
+ Debian Linux 2.2 powerpc
+ Debian Linux 2.2 IA-32
+ Debian Linux 2.2 arm
+ Debian Linux 2.2 alpha
+ Debian Linux 2.2 68k
+ Debian Linux 2.2
+ IBM AIX 4.3.3
+ SGI IRIX 6.5.19
+ SGI IRIX 6.5.18 m
+ SGI IRIX 6.5.18 f
+ SGI IRIX 6.5.17 m
+ SGI IRIX 6.5.17 f
+ SGI IRIX 6.5.16 m
+ SGI IRIX 6.5.16 f
+ SGI IRIX 6.5.15 m
+ SGI IRIX 6.5.15 f
+ SGI IRIX 6.5.14 m
+ SGI IRIX 6.5.14 f
+ SGI IRIX 6.5.13 m
+ SGI IRIX 6.5.13 f
+ SGI IRIX 6.5.12 m
+ SGI IRIX 6.5.12 f
+ SGI IRIX 6.5.11 m
+ SGI IRIX 6.5.11 f
+ SGI IRIX 6.5.10 m
+ SGI IRIX 6.5.10 f
+ SGI IRIX 6.5.9 m
+ SGI IRIX 6.5.9 f
+ SGI IRIX 6.5.8 m
+ SGI IRIX 6.5.8 f
+ SGI IRIX 6.5.7 m
+ SGI IRIX 6.5.7 f
Sendmail Consortium Sendmail 8.9.2
Sendmail Consortium Sendmail 8.9.1
Sendmail Consortium Sendmail 8.9 .0
Sendmail Consortium Sendmail 8.8.8
NetBSD NetBSD 1.6.1
NetBSD NetBSD 1.6 beta
NetBSD NetBSD 1.6
NetBSD NetBSD 1.5.3
NetBSD NetBSD 1.5.2
NetBSD NetBSD 1.5.1
NetBSD NetBSD 1.5 x86
NetBSD NetBSD 1.5 sh3
NetBSD NetBSD 1.5
NetBSD NetBSD 1.4.3
IBM AIX 4.3.3
IBM AIX 5.2
IBM AIX 5.1
HP HP-UX 11.22
HP HP-UX 11.11
HP HP-UX 11.0 4
HP HP-UX 11.0
Gentoo Linux 1.4 _rc3
Gentoo Linux 1.4 _rc2
Gentoo Linux 1.4 _rc1
Gentoo Linux 1.2
Gentoo Linux 1.1 a
Gentoo Linux 0.7
Gentoo Linux 0.5
FreeBSD FreeBSD 5.1 -RELENG
FreeBSD FreeBSD 5.1 -RELEASE-p5
FreeBSD FreeBSD 5.0 -RELENG
FreeBSD FreeBSD 5.0 -RELEASE-p14
FreeBSD FreeBSD 4.9 -PRERELEASE
FreeBSD FreeBSD 4.8 -RELENG
FreeBSD FreeBSD 4.8 -RELEASE-p7
FreeBSD FreeBSD 4.7 -RELENG
FreeBSD FreeBSD 4.7 -RELEASE-p17
FreeBSD FreeBSD 4.6 -RELENG
FreeBSD FreeBSD 4.6 -RELEASE-p20
FreeBSD FreeBSD 4.5 -RELENG
FreeBSD FreeBSD 4.5 -RELEASE-p32
FreeBSD FreeBSD 4.4 -RELENG
FreeBSD FreeBSD 4.4 -RELEASE-p42
FreeBSD FreeBSD 4.3 -RELENG
FreeBSD FreeBSD 4.3 -RELEASE-p38
FreeBSD FreeBSD 4.0 -RELENG
FreeBSD FreeBSD 3.0 -RELENG
Compaq Tru64 5.1 b PK2 (BL22)
Compaq Tru64 5.1 b PK1 (BL1)
Compaq Tru64 5.1 b
Compaq Tru64 5.1 a PK5 (BL23)
Compaq Tru64 5.1 a PK4 (BL21)
Compaq Tru64 5.1 a PK3 (BL3)
Compaq Tru64 5.1 a PK2 (BL2)
Compaq Tru64 5.1 a PK1 (BL1)
Compaq Tru64 5.1 a
Compaq Tru64 5.1 PK6 (BL20)
Compaq Tru64 5.1 PK5 (BL19)
Compaq Tru64 5.1 PK4 (BL18)
Compaq Tru64 5.1 PK3 (BL17)
Compaq Tru64 5.1
Compaq Tru64 4.0 g PK4 (BL22)
Compaq Tru64 4.0 g PK3 (BL17)
Compaq Tru64 4.0 g
Compaq Tru64 4.0 f PK8 (BL22)
Compaq Tru64 4.0 f PK7 (BL18)
Compaq Tru64 4.0 f PK6 (BL17)
Compaq Tru64 4.0 f
Apple Mac OS X Server 10.2.6
Apple Mac OS X Server 10.2.5
Apple Mac OS X Server 10.2.4
Apple Mac OS X Server 10.2.3
Apple Mac OS X Server 10.2.2
Apple Mac OS X Server 10.2.1
Apple Mac OS X Server 10.2
Apple Mac OS X 10.2.6
Apple Mac OS X 10.2.5
Apple Mac OS X 10.2.4
Apple Mac OS X 10.2.3
Apple Mac OS X 10.2.2
Apple Mac OS X 10.2.1
Apple Mac OS X 10.2
Not Vulnerable: SGI IRIX 6.5.22
SGI IRIX 6.5.14
SGI IRIX 6.5.13
SGI IRIX 6.5.12
SGI IRIX 6.5.11
SGI IRIX 6.5.10
SGI IRIX 6.5.9
SGI IRIX 6.5.8
SGI IRIX 6.5.7
SGI IRIX 6.5.6
SGI IRIX 6.5.5
SGI IRIX 6.5.4
SGI IRIX 6.5.3
SGI IRIX 6.5.2
SGI IRIX 6.5.1
Sendmail Consortium Sendmail 8.12.10
+ Slackware Linux 9.0
+ Slackware Linux 8.1
+ Slackware Linux 8.1
+ Slackware Linux -current
+ Slackware Linux -current
+ Sun Solaris 9_x86
+ Sun Solaris 9
+ Sun Solaris 8_x86
+ Sun Solaris 8_sparc
+ Sun Solaris 7.0_x86
+ Sun Solaris 7.0

Discussion

Sendmail Prescan() Variant Remote Buffer Overrun Vulnerability

Sendmail is prone to a buffer overrun vulnerability in the prescan() function. This issue is different than the vulnerability described in BID 7230. This vulnerability could permit remote attackers to execute arbitrary code via vulnerable versions of Sendmail.

Exploit / POC

Sendmail Prescan() Variant Remote Buffer Overrun Vulnerability

Gyan Chawdhary &lt;[email protected]&gt;, has supplied the following local proof of concept exploit:

Solution / Fix

Sendmail Prescan() Variant Remote Buffer Overrun Vulnerability

Solution:
The vendor has released Sendmail 8.12.10 to address this issue. Administrators are advised to upgrade if possible. A patch is also available which can be applied to other versions.

Sun have released fixes to address this vulnerability in Sun Linux 5.0.7. Users who are affected by this issue are advised to apply relevant fixes as soon as possible. Please see Sun reference (Sun Linux Support - Sun Linux Patches (Sun)) for further details regarding obtaining and applying appropriate fixes.

HP has released an advisory HPSBUX0309-281 to address this issue. Please see the referenced advisory for more information.

HP has issued an early release patch (t64kit0020132-v40gb22-es-20031001.tar) and a related readme (t64kit0020132-v40gb22-es-20031001.README) to address this issue in Tru64 4.0G systems. On October 22 of 2003, HP released t64v51ab-ix-553-sendmail-ssrt3631.README for Tru64, which contains updated fixes for Tru64 UNIX 5.1B PK2 (BL22), and t64v51ab-ix-586-sendmail-ssrt3631 and t64v51ab-ix-594-sendmail-ssrt3631 for Tru64 UNIX 5.0A. See referenced readmes for further details.

HP has released a revised advisory HPSBUX0309-281 to address this issue. HP has also released an advisory (SSRT3631) for Tru64 UNIX. An advisory corresponding to DUXKIT0020136-V40FB22-ES-20031001 for Tru64 UNIX has also been released. Please see the referenced advisories for further details.

New Tru64 advisories were released October 9, 2003 with new download links for patches. An additional Tru64 advisory (corresponding to T64V51AB21-C0112900-17770-ES-20030402) was also released October 10, 2003 that provides new download links for 5.1A fixes. Another Tru64 advisory (corresponding to T64V40GB17-C0029200-17810-ES-20030403) was released October 13, 2003 that provides new download links for updated 4.0G fixes. HP has released an updated advisory (t64kit0020139-v51b20-es-20031001) for HP Tru64 UNIX 5.1 PK6. Please see the referenced advisories for further information regarding updating and applying fixes.

SGI has released an advisory (20030903-01-P), to address this issue. Users are advised to download and apply a relevant patch as soon as possible. Further information relating to obtaining and applying appropriate fixes is available in the referenced advisory. Fixes are linked below.

Conectiva has released an advisory (CLA-2003:742), to address this issue. Users are advised to download and apply a relevant fixes as soon as possible. Further information relating to obtaining and applying appropriate fixes is available in the referenced advisory.

Turbolinux has released an advisory (TLSA-2003-52), to address this issue. Users are advised to download and apply a relevant fix as soon as possible. Further information relating to obtaining and applying appropriate fixes is available in the referenced advisory.

Yellow Dog Linux has released an advisory (YDU-20030917-2), to address this issue. Users are advised to download and apply a relevant fix as soon as possible. Further information relating to obtaining and applying appropriate fixes is available in the referenced advisory. Fixes are linked below.

Gentoo Linux has released an advisory (200309-13) to address this issue for Gentoo Linux users. Users who are running net-mail/sendmail are advised to upgrade to sendmail-8.2.10 by issuing the following commands as root:

emerge sync
emerge sendmail
emerge clean

Immunix has released an advisory (IMNX-2003-7+-021-01), to address this issue. Users are advised to download and apply a relevant fix as soon as possible. Further information relating to obtaining and applying appropriate fixes is available in the referenced advisory. Fixes are linked below.

FreeBSD has released an advisory (FreeBSD-SA-03:13.sendmail), to address this issue. Users are advised to download and apply the relevant patch as soon as possible. Further information relating to obtaining and applying appropriate patches is available in the referenced advisory.

Debian has issued fixes for this vulnerability that are listed in advisory [DSA-384-1] (see reference section).

Red Hat has issued fixes, listed in [RHSA-2003:283-01] (see reference section).

OpenPKG has released an advisory (OpenPKG-SA-2003.041) to address this issue. Please see the attached advisory for details on obtaining and applying fixes.

Conectiva has released an advisory (CLA-2003:746), to address this issue for CLEE 1.0. Users are advised to download and apply a relevant fixes as soon as possible. Please see the referenced advisory for more information.

SuSE has released an advisory SuSE-SA:2003:040 to address this issue. Please see the referenced advisory for more information.

Sun has released an alert for Solaris to address this issue. Affected users are advised to apply an available patch. Sun has also released an alert for
Sun Linux advising disabling sendmail on affected systems. See referenced advisories for additional details.

Apple has released security advisory APPLE-SA-2003-09-22 to address this issue. See referenced advisory for additional details.

IBM has issued an advisory. APARs to address this issue are available.

See the advisory, MSS-OAR-E01-2003:1235.1, in the reference section for complete installation details.

NetBSD has stated versions 1.5 through 1.6.1 are affected by this issue if sendmail is enabled, which is not the default configuration. See referenced advisory for additional details.

HP advisory SSRT3631 revision 2 has been released to address this issue. See referenced advisory for further details regarding obtaining and applying fixes. Additional fixes are available for HP Tru64 UNIX (IX) Internet Express systems that are running sendmail versions 8.9.3 through 8.12.9.

SCO has released a seucrity advisory for OpenLinux (CSSA-2003-036.0) which contains fixes to address this issue. Further information on how to obtain and apply fixes can be found in the referenced advisory.

Revised HP advisory SSRT3631 has released to address this issue.

Sun has released an update to address this in Sun RaQ550. Please see the referenced web page for more information.

IBM is said to have released APARs to address this issue. Further information can be obtained by contacting the vendor.

Revised HP advisory has been released to address this issue.

Sun has released an update to address this in Sun RaQXTR. Please see the referenced web page for more information.

Sun has released an update to address this in Sun Qube3. Please see the referenced web page for more information.

Sun has released an updated RaQ4 fix.

Revised HP advisory HPSBUX0309-281: SSRT3631 Rev.7 has been released to address this issue.

Revised HP advisory HPSBUX0309-281: SSRT3631 Rev.8 has been released to address this issue.

SCO has released a security advisory for OpenServer (SCOSA-2004.11) along with fixes to address this issue. Further information on how to obtain and apply fixes can be found in the referenced advisory.


Sun Solaris 8_sparc

IBM AIX 5.1

Sun Solaris 7.0

HP HP-UX 11.0 4

HP HP-UX 11.22

Compaq Tru64 4.0 g

FreeBSD FreeBSD 4.7 -RELENG

Sun Linux 5.0.7

FreeBSD FreeBSD 5.1 -RELENG

FreeBSD FreeBSD 5.1 -RELEASE-p5

SGI IRIX 6.5.16

SGI IRIX 6.5.17 m

SGI IRIX 6.5.19 f

SGI IRIX 6.5.20 f

SGI IRIX 6.5.20 m

SGI IRIX 6.5.21 m

Sendmail Consortium Sendmail 8.10

Sendmail Consortium Sendmail 8.10.1

Sendmail Consortium Sendmail 8.11

Sendmail Consortium Sendmail 8.11.2

Sendmail Consortium Sendmail 8.11.3

Sendmail Consortium Sendmail 8.11.4

Sendmail Consortium Sendmail 8.11.5

Sendmail Consortium Sendmail 8.11.6

Sendmail Consortium Sendmail 8.12 beta12

Sendmail Consortium Sendmail 8.12 beta5

Sendmail Consortium Sendmail 8.12.1

Sendmail Consortium Sendmail 8.12.3

Sendmail Consortium Sendmail 8.12.7

Sendmail Consortium Sendmail 8.12.8

Sendmail Consortium Sendmail 8.9 .0

Sendmail Consortium Sendmail 8.9.2

Sendmail Consortium Sendmail 8.9.3

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report