Vulnerabilities > CVE-2003-0688

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
redhat
sendmail
sgi
compaq
freebsd
openbsd
nessus

Summary

The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.

Nessus

  • NASL familySuSE Local Security Checks
    NASL idSUSE_SA_2003_035.NASL
    descriptionThe remote host is missing the patch for the advisory SUSE-SA:2003:035 (sendmail). The well known and widely used MTA sendmail is vulnerable to a remote denial-of-service attack in version 8.12.8 and earlier (but not before 8.12). The bug exists in the DNS map code. This feature is enabled by specifying FEATURE(`enhdnsbl
    last seen2020-06-01
    modified2020-06-02
    plugin id13803
    published2004-07-25
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/13803
    titleSUSE-SA:2003:035: sendmail
  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2003-086.NASL
    descriptionA vulnerability was discovered in all 8.12.x versions of sendmail up to and including 8.12.8. Due to wrong initialization of RESOURCE_RECORD_T structures, if sendmail receives a bad DNS reply it will call free() on random addresses which usually causes sendmail to crash. These updated packages are patched to fix the problem.
    last seen2020-06-01
    modified2020-06-02
    plugin id14068
    published2004-07-31
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/14068
    titleMandrake Linux Security Advisory : sendmail (MDKSA-2003:086)

Oval

accepted2010-09-20T04:00:31.764-04:00
classvulnerability
contributors
  • nameJay Beale
    organizationBastille Linux
  • nameJay Beale
    organizationBastille Linux
  • nameThomas R. Jones
    organizationMaitreya Security
  • nameJonathan Baker
    organizationThe MITRE Corporation
descriptionThe DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.
familyunix
idoval:org.mitre.oval:def:597
statusaccepted
submitted2003-09-05T12:00:00.000-04:00
titleDenial of Service in Sendmail via the enhdnsbl Feature
version41

Redhat

advisories
rhsa
idRHSA-2003:265