Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2003:284

The remote host is missing updates announced in
advisory RHSA-2003:284.

Sendmail is a widely used Mail Transport Agent (MTA) and is included in all
Red Hat Enterprise Linux distributions.

There is a bug in the prescan() function of Sendmail versions prior to and
including 8.12.9. The sucessful exploitation of this bug can lead to heap
and stack structure overflows. Although no exploit currently exists, this
issue is locally exploitable and may also be remotely exploitable.
The Common Vulnerabilities and Exposures project ( has
assigned the name CVE-2003-0694 to this issue.

All users are advised to update to these erratum packages containing a
backported patch which corrects these vulnerabilities.

Red Hat would like to thank Michal Zalewski for finding and reporting this

Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

Risk factor : Critical

CVSS Score:

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2003-0694
Bugtraq: 20030917 GLSA: sendmail (200309-13) (Google Search)
Bugtraq: 20030917 Sendmail 8.12.9 prescan bug (a new one) [CAN-2003-0694] (Google Search)
Bugtraq: 20030917 [slackware-security] Sendmail vulnerabilities fixed (SSA:2003-260-02) (Google Search)
Bugtraq: 20030919 [OpenPKG-SA-2003.041] OpenPKG Security Advisory (sendmail) (Google Search)
CERT/CC vulnerability note: VU#784980
Conectiva Linux advisory: CLA-2003:742
Debian Security Information: DSA-384 (Google Search)
FreeBSD Security Advisory: FreeBSD-SA-03:13
HPdes Security Advisory: SSRT3631
Immunix Linux Advisory: IMNX-2003-7+-021-01
SCO Security Bulletin: CSSA-2003-036.0
SCO Security Bulletin: SCOSA-2004.11
CopyrightCopyright (c) 2005 E-Soft Inc.

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

© 1998-2021 E-Soft Inc. All rights reserved.