Publisher Name: OpenPKG GmbH Publisher Home: http://openpkg.com/ Advisory Id (public): OpenPKG-SA-2003.027 Advisory Type: OpenPKG Security Advisory (SA) Advisory Directory: http://openpkg.com/go/OpenPKG-SA Advisory Document: http://openpkg.com/go/OpenPKG-SA-2003.027 Advisory Published: 2010-09-03 22:20 UTC Issue Id (internal): OpenPKG-SI-20030330.01 Issue First Created: 2003-03-30 Issue Last Modified: 2006-11-28 Issue Revision: 06
Subject Name: Sendmail Subject Summary: Mail Transfer Agent Subject Home: http://www.sendmail.org/ Subject Versions: * <= 8.12.8 Vulnerability Id: CVE-2003-0161 Vulnerability Scope: global (not OpenPKG specific) Attack Feasibility: run-time Attack Vector: remote network Attack Impact: privilege escalation Description: Michal Zalewski discovered [1] a confirmed [2] buffer overflow vulnerability in all version of the Sendmail [0] MTA earlier than 8.12.9. The mail address parser performs insufficient bounds checking in certain conditions due to a "char" to "int" data type conversion, making it possible for an attacker to take control of the application. Attackers may remotely exploit this vulnerability to gain "root" access of any vulnerable Sendmail server. References: [0] http://www.sendmail.org/ [1] http://lists.netsys.com/pipermail/full-disclosure/2003-March/008973.html [2] http://www.securityfocus.com/archive/1/316760/2003-03-26/2003-04-01/0 [3] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0161 [4] http://www.openpkg.org/tutorial.html#regular-source [5] http://www.openpkg.org/tutorial.html#regular-binary [6] ftp://ftp.openpkg.org/release/1.2/UPD/sendmail-8.12.7-1.2.2.src.rpm [7] ftp://ftp.openpkg.org/release/1.2/UPD/ [8] http://www.openpkg.org/security.html#signature
Primary Package Name: sendmail Primary Package Home: http://openpkg.org/go/package/sendmail Affected Distribution: Affected Branch: Affected Package: OpenPKG Community 1.1-SOLID n/a OpenPKG Community 1.2-SOLID sendmail-8.12.7-1.2.1 OpenPKG Community CURRENT sendmail-8.12.8-20030328 Corrected Distribution: Corrected Branch: Corrected Package: OpenPKG Community 1.1-SOLID n/a OpenPKG Community 1.2-SOLID sendmail-8.12.7-1.2.2 OpenPKG Community CURRENT sendmail-8.12.9-20030329