Description
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
Affected products
- Apple / mac_os_x10.2.6 – 10.2.6
- Apple / mac_os_x10.2 – 10.2
- Apple / mac_os_x10.2.1 – 10.2.1
- Apple / mac_os_x10.2.2 – 10.2.2
- Apple / mac_os_x10.2.3 – 10.2.3
- Apple / mac_os_x10.2.4 – 10.2.4
- Apple / mac_os_x10.2.5 – 10.2.5
- Apple / mac_os_x_server10.2.4 – 10.2.4
- Apple / mac_os_x_server10.2 – 10.2
- Apple / mac_os_x_server10.2.1 – 10.2.1
- Apple / mac_os_x_server10.2.2 – 10.2.2
- Apple / mac_os_x_server10.2.3 – 10.2.3
- Apple / mac_os_x_server10.2.6 – 10.2.6
- Apple / mac_os_x_server10.2.5 – 10.2.5
- gentoo / linux0.7 – 0.7
- gentoo / linux1.4 – 1.4
- gentoo / linux1.4 – 1.4
- gentoo / linux1.4 – 1.4
- gentoo / linux1.2 – 1.2
- gentoo / linux1.1a – 1.1a
- gentoo / linux0.5 – 0.5
- HP / hp-ux11.00 – 11.00
- HP / hp-ux11.22 – 11.22
- HP / hp-ux11.11 – 11.11
- HP / hp-ux11.0.4 – 11.0.4
- ibm / aix5.2 – 5.2
- ibm / aix5.1 – 5.1
- ibm / aix4.3.3 – 4.3.3
- NetBSD / netbsd1.5 – 1.5
- NetBSD / netbsd1.5 – 1.5
- NetBSD / netbsd1.5.1 – 1.5.1
- NetBSD / netbsd1.5.2 – 1.5.2
- NetBSD / netbsd1.5.3 – 1.5.3
- NetBSD / netbsd1.6 – 1.6
- NetBSD / netbsd1.6 – 1.6
- NetBSD / netbsd1.6.1 – 1.6.1
- NetBSD / netbsd1.4.3 – 1.4.3
- NetBSD / netbsd1.5 – 1.5
- OpenBSD / OpenBSD3.3 – 3.3
- OpenBSD / OpenBSD3.2 – 3.2
- sendmail / advanced_message_server1.2 – 1.2
- sendmail / advanced_message_server1.3 – 1.3
- sendmail / sendmail8.12 – 8.12
- sendmail / sendmail2.6 – 2.6
- sendmail / sendmail2.6.1 – 2.6.1
- sendmail / sendmail2.6.2 – 2.6.2
- sendmail / sendmail3.0 – 3.0
- sendmail / sendmail3.0.1 – 3.0.1
- sendmail / sendmail3.0.2 – 3.0.2
- sendmail / sendmail3.0.3 – 3.0.3
- sendmail / sendmail8.8.8 – 8.8.8
- sendmail / sendmail8.9.0 – 8.9.0
- sendmail / sendmail8.9.1 – 8.9.1
- sendmail / sendmail8.9.2 – 8.9.2
- sendmail / sendmail8.9.3 – 8.9.3
- sendmail / sendmail8.10 – 8.10
- sendmail / sendmail8.10.1 – 8.10.1
- sendmail / sendmail8.10.2 – 8.10.2
- sendmail / sendmail8.11.0 – 8.11.0
- sendmail / sendmail8.11.1 – 8.11.1
- sendmail / sendmail8.11.2 – 8.11.2
- sendmail / sendmail8.11.3 – 8.11.3
- sendmail / sendmail8.11.4 – 8.11.4
- sendmail / sendmail8.11.5 – 8.11.5
- sendmail / sendmail8.11.6 – 8.11.6
- sendmail / sendmail8.12 – 8.12
- sendmail / sendmail8.12 – 8.12
- sendmail / sendmail8.12 – 8.12
- sendmail / sendmail8.12 – 8.12
- sendmail / sendmail8.12.0 – 8.12.0
- sendmail / sendmail8.12.1 – 8.12.1
- sendmail / sendmail8.12.2 – 8.12.2
- sendmail / sendmail8.12.3 – 8.12.3
- sendmail / sendmail8.12.4 – 8.12.4
- sendmail / sendmail8.12.5 – 8.12.5
- sendmail / sendmail8.12.6 – 8.12.6
- sendmail / sendmail8.12.7 – 8.12.7
- sendmail / sendmail8.12.8 – 8.12.8
- sendmail / sendmail8.12.9 – 8.12.9
- sendmail / sendmail_pro8.9.3 – 8.9.3
- sendmail / sendmail_pro8.9.2 – 8.9.2
- sendmail / sendmail_switch3.0.1 – 3.0.1
- sendmail / sendmail_switch3.0 – 3.0
- sendmail / sendmail_switch2.2.5 – 2.2.5
- sendmail / sendmail_switch2.2.4 – 2.2.4
- sendmail / sendmail_switch2.2.3 – 2.2.3
- sendmail / sendmail_switch2.2.2 – 2.2.2
- sendmail / sendmail_switch2.2.1 – 2.2.1
- sendmail / sendmail_switch2.2 – 2.2
- sendmail / sendmail_switch2.1.5 – 2.1.5
- sendmail / sendmail_switch2.1.4 – 2.1.4
- sendmail / sendmail_switch2.1.3 – 2.1.3
- sendmail / sendmail_switch2.1.2 – 2.1.2
- sendmail / sendmail_switch2.1.1 – 2.1.1
- sendmail / sendmail_switch2.1 – 2.1
- sendmail / sendmail_switch3.0.3 – 3.0.3
- sendmail / sendmail_switch3.0.2 – 3.0.2
- turbolinux / turbolinux_advanced_server6.0 – 6.0
- turbolinux / turbolinux_server6.1 – 6.1
- turbolinux / turbolinux_server6.5 – 6.5
- turbolinux / turbolinux_server7.0 – 7.0
- turbolinux / turbolinux_server8.0 – 8.0
- turbolinux / turbolinux_workstation6.0 – 6.0
- turbolinux / turbolinux_workstation7.0 – 7.0
- turbolinux / turbolinux_workstation8.0 – 8.0
References
- MAILING_LISThttp://marc.info/?l=bugtraq&m=106398718909274&w=2
- MISChttp://www.sendmail.org/8.12.10.html
- MISChttp://www.redhat.com/support/errata/RHSA-2003-283.html
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A595
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDKSA-2003:092
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3606
- MISChttp://www.kb.cert.org/vuls/id/108964
- VENDOR_ADVISORYhttp://www.debian.org/security/2003/dsa-384
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/13216
- MAILING_LISThttp://marc.info/?l=bugtraq&m=106383437615742&w=2
- MISChttp://www.securityfocus.com/bid/8649
- MISChttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000742