CVE-2003-0688
Last modified
CVE-2003-0688 is a vulnerability of currently unknown severity. The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.. EPSS estimates a 3.34% chance of exploitation in the next 30 days.
Description
The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Sendmail | 8.12.5-7 |
| Redhat | Sendmail | 8.12.8-4 |
| Sendmail | Sendmail | 8.12.1 |
| Sendmail | Sendmail | 8.12.2 |
| Sendmail | Sendmail | 8.12.3 |
| Sendmail | Sendmail | 8.12.4 |
| Sendmail | Sendmail | 8.12.5 |
| Sendmail | Sendmail | 8.12.6 |
| Sendmail | Sendmail | 8.12.7 |
| Sendmail | Sendmail | 8.12.8 |
| Sgi | Irix | 6.5.19 |
| Sgi | Irix | 6.5.20 |
| Sgi | Irix | 6.5.21 |
| Compaq | Tru64 | 5.0a |
| Compaq | Tru64 | 5.1 |
| Freebsd | Freebsd | 4.6 |
| Freebsd | Freebsd | 4.7 |
| Freebsd | Freebsd | 4.8 |
| Freebsd | Freebsd | 5.0 |
| Openbsd | Openbsd | 3.2 |
References
- http://www.kb.cert.org/vuls/id/993452US Government Resource
- http://www.redhat.com/support/errata/RHSA-2003-265.htmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/993452US Government Resource
- http://www.redhat.com/support/errata/RHSA-2003-265.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-0688?
How severe is CVE-2003-0688?
How do I fix CVE-2003-0688?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2003
- CVE-2003-0682"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown imp…
- CVE-2003-0683NFS in SGI 6.5.21m and 6.5.21f does not perform access check…
- CVE-2003-0684Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2003-0685Buffer overflow in Netris 0.52 and earlier, and possibly oth…
- CVE-2003-0686Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlie…
- CVE-2003-0687Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2003-0689The getgrouplist function in GNU libc (glibc) 2.2.4 and earl…
- CVE-2003-0690KDM in KDE 3.1.3 and earlier does not verify whether the pam…
- CVE-2003-0691Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2003-0692KDM in KDE 3.1.3 and earlier uses a weak session cookie gene…
- CVE-2003-0693A "buffer management error" in buffer_append_space of buffer…
- CVE-2003-0694The prescan function in Sendmail 8.12.9 allows remote attack…
Are you affected by CVE-2003-0688?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
