Vulnerability record · CVE-2002-1337 · published 7 March 2003
CVE-2002-1337: Sendmail crackaddr buffer overflow allows remote code execution
Sendmail · Sendmail
Sendmail versions 5.79 through 8.12.7 contain a buffer overflow in the crackaddr function in headers.c, triggered by specially formatted sender and recipient header comments. Because the flaw is reachable through mail header processing, it exposes mail servers to remote compromise without any prior authentication.
Description
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score is 10.0 with complete confidentiality, integrity, and availability impact, and the flaw is remotely exploitable without authentication.
What it is
Sendmail versions 5.79 through 8.12.7 contain a buffer overflow in the crackaddr function in headers.c, triggered by specially formatted sender and recipient header comments. Because the flaw is reachable through mail header processing, it exposes mail servers to remote compromise without any prior authentication.
Impact
A remote attacker can execute arbitrary code with the privileges of the Sendmail process, which typically runs as root or a privileged user. This can lead to full host compromise and use of the mail server as a pivot point.
Attack surface
The vulnerability is reached over the network by sending a crafted email message whose address header comments are parsed by crackaddr. No authentication or user interaction is required; the vector is AV:N/AC:L/Au:N.
Exploitation
The record is not listed in CISA KEV, but EPSS is very high at 0.72644 (99.4th percentile), and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Sendmail to 8.12.8 or later, or apply the vendor patch referenced in the Sendmail 8.12.8 advisory.
- Apply operating system vendor updates for Sendmail packages (Red Hat, Debian, NetBSD, HP-UX, Solaris, SCO, IBM, SGI, Mandriva, Conectiva).
- If immediate patching is not possible, restrict SMTP access to trusted relays and disable unnecessary mail acceptance from untrusted networks.
- Run Sendmail with reduced privileges where supported and monitor for unexpected process behavior.
- Review mail gateway filtering to reject malformed address header comments as a temporary compensating control.
Detection
- Inspect mail logs for crashes, restarts, or abnormal Sendmail process terminations correlated with inbound messages containing unusual address header comments.
- Monitor for unexpected child processes or command execution spawned by the Sendmail daemon.
- Use network or host IDS signatures for known Sendmail crackaddr exploit traffic if available.
- Audit Sendmail versions across the estate to identify any host still running 5.79 through 8.12.7.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-1337 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-1337), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.