CVE-2002-1337General(gentoo / alphaserver_sc)

LOWCVSS 10.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • alphaserver_sc
  • bsdos
  • hp-ux
  • linux

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
alphaserver_scbsdoshp-uxlinuxnetbsdplatform_sasendmailsolarissunos

23 versions affected across 9 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-13: 1Technical Details · 2026-04-13: 104-13
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Vincenzo Iozzo@_vincenzoiozzo
    General

    Given all the news about Mythos,  I ran a small experiment testing Opus 4.6 to understand a bit better how it finds bugs. The setup was: Sendmail crackaddr() bug (CVE-2002-1337) — the original source, a rewritten equivalent, a compiled binary with symbols, and an obfuscated stripped binary. The model found the bug quickly in the first three cases (under 3-4 minutes). The obfuscated version took ~45 minutes of actual "reasoning". A few things stood out: - The model behaves like a human bug hunter would: switching between "pattern matching" and dynamic analysis, using runtime feedback as an oracle - Having an oracle is crucially important. So much so that the agent constructed its own when instructed not to run the binary - The gap between "pattern matching" and "reasoning" capabilities seems significant. The latter appears fairly primitive for Opus. Is Mythos better purely because of the much larger context window or is it something else? - Opus behaves deceptively fairly often. It's surprising how much a hidden scratchpad helps (this is similar to the Sleeper Agents approach) Full writeup: https://vincenzoiozzo.com/blog/alphago-moment-vuln-research

    Post summary

    The write‑up reports a research experiment using the Mythos/Opus model to detect a known Sendmail bug (CVE‑2002‑1337), highlighting detection efficiency but providing no PoC, exploit, or patch information.

    341218715818.8K
    5.2K followersView on X
CPE platform detail26 entries

26 of 26 entries

PartVendorProductVersionTarget SWTarget HW
OSgentoolinux1.4--
OSgentoolinux1.4--
HWhpalphaserver_sc---
OShphp-ux10.10--
OShphp-ux10.20--
OShphp-ux11.0.4--
OShphp-ux11.00--
OShphp-ux11.11--
OShphp-ux11.22--
OSnetbsdnetbsd1.5--
OSnetbsdnetbsd1.5.1--
OSnetbsdnetbsd1.5.2--
OSnetbsdnetbsd1.5.3--
OSnetbsdnetbsd1.6--
OSoraclesolaris2.6--
OSoraclesolaris7.0--
OSoraclesolaris8--
OSoraclesolaris9--
Appsendmailsendmail---
OSsunsunos---
OSsunsunos5.7--
OSsunsunos5.8--
OSwindriverbsdos4.2--
OSwindriverbsdos4.3.1--
OSwindriverbsdos5.0--
OSwindriverplatform_sa1.0--

Explore more