CVE-2003-0161

NameCVE-2003-0161
DescriptionThe prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-278, DSA-290

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
sendmail (PTS)jessie8.14.4-8+deb8u2fixed
stretch (lts), stretch8.15.2-8+deb9u2fixed
buster (security), buster, buster (lts)8.15.2-14~deb10u3fixed
bullseye8.15.2-22+deb11u3fixed
bookworm8.17.1.9-2+deb12u2fixed
sid, trixie8.18.1-6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
sendmailsourcewoody8.12.3-6.3DSA-278
sendmailsource(unstable)8.12.9-1
sendmail-widesourcewoody8.12.3+3.5Wbeta-5.4DSA-290
sendmail-widesource(unstable)8.12.9+3.5Wbeta-1

Search for package or bug name: Reporting problems