CVE-2003-0688 Affecting sendmail package, versions <8.12.9


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
5.7% (94th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN8-SENDMAIL-310638
  • published20 Oct 2003
  • disclosed20 Oct 2003

Introduced: 20 Oct 2003

CVE-2003-0688  (opens in a new tab)

How to fix?

Upgrade Debian:8 sendmail to version 8.12.9 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream sendmail package and not the sendmail package as distributed by Debian. See How to fix? for Debian:8 relevant fixed versions and status.

The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.

CVSS Base Scores

version 3.1