Summary
The remote host is missing an update to sendmail
announced via advisory DSA 384-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20384-1
Insight
Two vulnerabilities were reported in sendmail.
- CVE-2003-0681
A 'potential buffer overflow in ruleset parsing' for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
- CVE-2003-0694
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
For the stable distribution (woody) these problems have been fixed in sendmail version 8.12.3-6.6 and sendmail-wide version 8.12.3+3.5Wbeta-5.5.
For the unstable distribution (sid) these problems have been fixed in sendmail version 8.12.10-1.
We recommend that you update your sendmail package.
Severity
Classification
-
CVE CVE-2003-0681, CVE-2003-0694 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities