← Vulnerability feed

Vulnerability record · CVE-2002-1337 · published 7 March 2003

CVE-2002-1337: Sendmail crackaddr buffer overflow allows remote code execution

Sendmail · Sendmail

Sendmail versions 5.79 through 8.12.7 contain a buffer overflow in the crackaddr function in headers.c, triggered by specially formatted sender and recipient header comments. Because the flaw is reachable through mail header processing, it exposes mail servers to remote compromise without any prior authentication.

10.0 CVSS 2.0 High EPSS 73% · top 0.6% CWE-120 · Classic buffer overflow
10.0CVSS 2.0 base score
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
50References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 2.0 base score is 10.0 with complete confidentiality, integrity, and availability impact, and the flaw is remotely exploitable without authentication.

What it is

Sendmail versions 5.79 through 8.12.7 contain a buffer overflow in the crackaddr function in headers.c, triggered by specially formatted sender and recipient header comments. Because the flaw is reachable through mail header processing, it exposes mail servers to remote compromise without any prior authentication.

Impact

A remote attacker can execute arbitrary code with the privileges of the Sendmail process, which typically runs as root or a privileged user. This can lead to full host compromise and use of the mail server as a pivot point.

Attack surface

The vulnerability is reached over the network by sending a crafted email message whose address header comments are parsed by crackaddr. No authentication or user interaction is required; the vector is AV:N/AC:L/Au:N.

Exploitation

The record is not listed in CISA KEV, but EPSS is very high at 0.72644 (99.4th percentile), and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade Sendmail to 8.12.8 or later, or apply the vendor patch referenced in the Sendmail 8.12.8 advisory.
  • Apply operating system vendor updates for Sendmail packages (Red Hat, Debian, NetBSD, HP-UX, Solaris, SCO, IBM, SGI, Mandriva, Conectiva).
  • If immediate patching is not possible, restrict SMTP access to trusted relays and disable unnecessary mail acceptance from untrusted networks.
  • Run Sendmail with reduced privileges where supported and monitor for unexpected process behavior.
  • Review mail gateway filtering to reject malformed address header comments as a temporary compensating control.

Detection

  • Inspect mail logs for crashes, restarts, or abnormal Sendmail process terminations correlated with inbound messages containing unusual address header comments.
  • Monitor for unexpected child processes or command execution spawned by the Sendmail daemon.
  • Use network or host IDS signatures for known Sendmail crackaddr exploit traffic if available.
  • Audit Sendmail versions across the estate to identify any host still running 5.79 through 8.12.7.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-002.txt.asc Broken Link
ftp://ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.6 Broken Link
ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.5 Broken Link
ftp://patches.sgi.com/support/free/security/advisories/20030301-01-P Broken Link
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000571 Broken Link
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:028 Broken Link
http://marc.info/?l=bugtraq&m=104673778105192&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=104678739608479&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=104678862109841&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=104678862409849&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=104679411316818&w=2 Third Party Advisory
http://www-1.ibm.com/support/search.wss?rs=0&q=IY40500&apar=only Broken Link
http://www-1.ibm.com/support/search.wss?rs=0&q=IY40501&apar=only Broken Link
http://www-1.ibm.com/support/search.wss?rs=0&q=IY40502&apar=only Broken Link
http://www.cert.org/advisories/CA-2003-07.html Broken LinkPatchThird Party AdvisoryUS Government Resource
http://www.debian.org/security/2003/dsa-257 Broken Link
http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21950 Broken LinkPatchVendor Advisory
http://www.iss.net/security_center/static/10748.php Broken Link
http://www.kb.cert.org/vuls/id/398025 Third Party AdvisoryUS Government Resource
http://www.redhat.com/support/errata/RHSA-2003-073.html Broken Link
http://www.redhat.com/support/errata/RHSA-2003-074.html Broken Link
http://www.redhat.com/support/errata/RHSA-2003-227.html Broken Link
http://www.securityfocus.com/bid/6991 Broken LinkExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
http://www.sendmail.org/8.12.8.html Broken LinkPatchVendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2222 Broken Link
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-002.txt.asc Broken Link
ftp://ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.6 Broken Link
ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.5 Broken Link
ftp://patches.sgi.com/support/free/security/advisories/20030301-01-P Broken Link
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000571 Broken Link
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:028 Broken Link
http://marc.info/?l=bugtraq&m=104673778105192&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=104678739608479&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=104678862109841&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=104678862409849&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=104679411316818&w=2 Third Party Advisory
http://www-1.ibm.com/support/search.wss?rs=0&q=IY40500&apar=only Broken Link
http://www-1.ibm.com/support/search.wss?rs=0&q=IY40501&apar=only Broken Link
http://www-1.ibm.com/support/search.wss?rs=0&q=IY40502&apar=only Broken Link
http://www.cert.org/advisories/CA-2003-07.html Broken LinkPatchThird Party AdvisoryUS Government Resource

Track CVE-2002-1337 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-14871Oracle Solaris PAM out-of-bounds write allows remote unauthenticated takeoverOracle Solaris 10 and 11 contain an out-of-bounds write (CWE-787) in the Pluggable Authentication Module component, reachable over the network withou…KEVEPSS 80%analysed9.8CVE-2012-1823PHP-CGI query string option injection enables remote code executionPHP versions before 5.3.12 and 5.4.x before 5.4.2, when run as a CGI script (php-cgi), mishandle query strings that lack an equals sign, allowing com…KEVEPSS 100%analysed8.8CVE-2019-3010Oracle Solaris XScreenSaver local privilege escalationA flaw in the XScreenSaver component of Oracle Solaris 11 allows a low-privileged user with a local logon to escalate privileges and take over the sy…KEVEPSS 13%analysed8.8CVE-2015-4495Firefox PDF reader same-origin bypass allows file read and privilege gainThe PDF reader in Mozilla Firefox (before 39.0.3), Firefox ESR 38.x (before 38.1.1), and Firefox OS (before 2.2) fails to properly validate origin, l…KEVEPSS 69%analysed7.8CVE-2008-2992Adobe Acrobat and Reader util.printf Stack Buffer OverflowAdobe Acrobat and Reader 8.1.2 and earlier contain a stack-based buffer overflow reachable through the util.printf JavaScript function when it is pas…KEVEPSS 98%analysed5.5CVE-2016-3718ImageMagick HTTP/FTP coders allow server-side request forgery via crafted imageImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 mishandles the HTTP and FTP coders, letting a crafted image trigger server-side request forgery. A…KEVEPSS 77%analysed5.5CVE-2016-3715ImageMagick EPHEMERAL coder allows arbitrary file deletionThe EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 lets a crafted image cause deletion of arbitrary files. This is part of the…KEVEPSS 75%analysed10.0CVE-2026-46978Oracle solaris improper access control vulnerabilityVulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported version that is affected is 11…EPSS 0.43%

Source: NIST National Vulnerability Database (record CVE-2002-1337), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.