HIGH · 10.0

CVE-2002-1337

Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the c...

Vulnerability Description

Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
SendmailSendmail< 8.9.3
HpAlphaserver ScAll versions
GentooLinux1.4
HpHp-Ux10.10
NetbsdNetbsd1.5
OracleSolaris2.6
SunSunos-
WindriverBsdos4.2
WindriverPlatform Sa1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2002-1337?

CVE-2002-1337 is a vulnerability with a CVSS score of 10.0 (HIGH). Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the c...

How severe is CVE-2002-1337?

CVE-2002-1337 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-1337?

Check the references section above for vendor advisories and patch information. Affected products include: Sendmail Sendmail, Hp Alphaserver Sc, Gentoo Linux, Hp Hp-Ux, Netbsd Netbsd.