CVE-2002-1337
45Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 72%
from disclosure to weapon0 days
Published on NVDSep 1
1st PoCJan 1
exploitation probability
72%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.
Affected products
n/a · n/apublic PoCs found — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/22314exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/411exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/22313⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-002.txt.ascftp://ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.6ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.5ftp://patches.sgi.com/support/free/security/advisories/20030301-01-Phttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000571http://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:028http://marc.info/?l=bugtraq&m=104673778105192&w=2http://marc.info/?l=bugtraq&m=104678739608479&w=2http://marc.info/?l=bugtraq&m=104678862109841&w=2http://marc.info/?l=bugtraq&m=104678862409849&w=2http://marc.info/?l=bugtraq&m=104679411316818&w=2https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2222