Sendmail是一款互联网上最流行的邮件传输代理(MTA)。 Sendmail中的prescan()函数(与 http://www.nsfocus.net/index.php?act=sec_bug&do=view&bug_id=4625 描述的漏洞不同)存在问题,远程攻击者可以利用这个漏洞可能以Sendmail进程权限在系统上执行任意指令。 在Linux上的本地利用方法可以通过recipient.c和sendtolist(),利用用户提交的数据覆盖指针,在调用free()函数时可能导致指令重定向,攻击
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2003-0680 | SGI IRIX NFS Export未授权Read/Write mount漏洞 | |
| CVE-2003-0681 | Sendmail Ruleset Parsing 缓冲区溢出漏洞 | |
| CVE-2003-0682 | OpenSSH漏洞 | |
| CVE-2003-0690 | KDE KDM PAM模块PAM_SetCred权限提升漏洞 | |
| CVE-2003-0692 | KDE KDM会话Cookie生成漏洞 | |
| CVE-2003-0695 | OpenSSH 缓冲区管理错误漏洞 | |
| CVE-2003-0801 | Nokia Electronic Documentation (NED)跨站脚本漏洞 | |
| CVE-2003-0802 | Nokia Electronic Documentation目录信息泄露漏洞 | |
| CVE-2003-0803 | Nokia Electronic Documentation连接重定向漏洞 |
No comments yet