CVE-2002-0391
published 2002-08-12CVE-2002-0391: Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows…
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
58.13%
99.0th percentile
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
Affected
172 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cray | unicos | — | — |
| cray | unicos | — | — |
| cray | unicos | — | — |
| cray | unicos | — | — |
| cray | unicos | — | — |
| cray | unicos | — | — |
| cray | unicos | — | — |
| cray | unicos | — | — |
| cray | unicos | — | — |
| cray | unicos | — | — |
| debian | acm | < acm 5.0-10 (bookworm) | acm 5.0-10 (bookworm) |
| debian | dietlibc | < dietlibc 0.22-2 (bookworm) | dietlibc 0.22-2 (bookworm) |
| debian | dietlibc | < acm 5.0-10 (bookworm) | acm 5.0-10 (bookworm) |
| debian | glibc | < dietlibc 0.22-2 (bookworm) | dietlibc 0.22-2 (bookworm) |
| debian | glibc | < acm 5.0-10 (bookworm) | acm 5.0-10 (bookworm) |
| debian | krb5 | < dietlibc 0.22-2 (bookworm) | dietlibc 0.22-2 (bookworm) |
| debian | krb5 | < acm 5.0-10 (bookworm) | acm 5.0-10 (bookworm) |
| debian | openafs | < acm 5.0-10 (bookworm) | acm 5.0-10 (bookworm) |
| freebsd | freebsd | <= 4.6.1 | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target RPC services known to be exploitable via xdr_array integer overflow: rpc.cmsd and dmispd. Monitor for anomalous RPC calls to these services with unusually large argument counts. ↗
- →The vulnerable function is xdr_array in SunRPC-derived libraries (libc, glibc, dietlibc). Inspect RPC traffic for integer overflow conditions triggered by excessively large array size fields in XDR-encoded requests. ↗
- ·Vulnerability affects multiple SunRPC-derived library implementations across different operating systems; scope of affected systems is broad. ↗
- ·Debian packages have resolved CVE-2002-0391 at version 5.0-10 across bookworm, bullseye, sid, and trixie; verify package versions when assessing exposure. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2qf2-q2gj-r6v2: Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, al
ghsa_unreviewed·2022-05-03
CVE-2002-0391 [HIGH] GHSA-2qf2-q2gj-r6v2: Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, al
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
OSV
CVE-2002-0391: Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, al
osv·2002-08-12·CVSS 9.8
CVE-2002-0391 [CRITICAL] CVE-2002-0391: Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, al
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
Red Hat
security flaw
vendor_redhat·2003-03-19·CVSS 9.8
CVE-2003-0028 [CRITICAL] security flaw
security flaw
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
Debian
CVE-2003-0028: dietlibc - Integer overflow in the xdrmem_getbytes() function, and possibly other functions...
vendor_debian·2003·CVSS 9.8
CVE-2003-0028 [CRITICAL] CVE-2003-0028: dietlibc - Integer overflow in the xdrmem_getbytes() function, and possibly other functions...
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
Scope: local
bookworm: resolved (fixed in 0.22-2)
bullseye: resolved (fixed in 0.22-2)
forky: resolved (fixed in 0.22-2)
sid: resolved (fixed in 0.22-2)
trixie: resolved (fixed in 0.22-2)
Red Hat
security flaw
vendor_redhat·2002-07-29·CVSS 9.8
CVE-2002-0391 [CRITICAL] security flaw
security flaw
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
Debian
CVE-2002-0391: acm - Integer overflow in xdr_array function in RPC servers for operating systems that...
vendor_debian·2002·CVSS 9.8
CVE-2002-0391 [CRITICAL] CVE-2002-0391: acm - Integer overflow in xdr_array function in RPC servers for operating systems that...
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
Scope: local
bookworm: resolved (fixed in 5.0-10)
bullseye: resolved (fixed in 5.0-10)
sid: resolved (fixed in 5.0-10)
trixie: resolved (fixed in 5.0-10)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2003-0028 security flaw
bugzilla·2018-08-16·CVSS 9.8
CVE-2003-0028 [CRITICAL] CVE-2003-0028 security flaw
CVE-2003-0028 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
Bugzilla
CVE-2002-0391 security flaw
bugzilla·2018-08-16·CVSS 9.8
CVE-2002-0391 [CRITICAL] CVE-2002-0391 security flaw
CVE-2002-0391 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-055.0.txtftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-011.txt.ascftp://patches.sgi.com/support/free/security/advisories/20020801-01-Aftp://patches.sgi.com/support/free/security/advisories/20020801-01-Phttp://archives.neohapsis.com/archives/aix/2002-q4/0002.htmlhttp://archives.neohapsis.com/archives/bugtraq/2002-07/0514.htmlhttp://archives.neohapsis.com/archives/hp/2002-q3/0077.htmlhttp://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20823http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000515http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000535http://marc.info/?l=bugtraq&m=102813809232532&w=2http://marc.info/?l=bugtraq&m=102821785316087&w=2http://marc.info/?l=bugtraq&m=102821928418261&w=2http://marc.info/?l=bugtraq&m=102831443208382&w=2http://marc.info/?l=bugtraq&m=103158632831416&w=2http://online.securityfocus.com/advisories/4402http://online.securityfocus.com/archive/1/285740http://rhn.redhat.com/errata/RHSA-2002-166.htmlhttp://rhn.redhat.com/errata/RHSA-2002-172.htmlhttp://www.cert.org/advisories/CA-2002-25.htmlhttp://www.debian.org/security/2002/dsa-142http://www.debian.org/security/2002/dsa-143http://www.debian.org/security/2002/dsa-146http://www.debian.org/security/2002/dsa-149http://www.debian.org/security/2003/dsa-333http://www.iss.net/security_center/static/9170.phphttp://www.kb.cert.org/vuls/id/192995http://www.linuxsecurity.com/advisories/other_advisory-2399.htmlhttp://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:057http://www.redhat.com/support/errata/RHSA-2002-167.htmlhttp://www.redhat.com/support/errata/RHSA-2002-173.htmlhttp://www.redhat.com/support/errata/RHSA-2003-168.htmlhttp://www.redhat.com/support/errata/RHSA-2003-212.htmlhttp://www.securityfocus.com/bid/5356https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-057https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A42https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4728https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-055.0.txtftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-011.txt.ascftp://patches.sgi.com/support/free/security/advisories/20020801-01-Aftp://patches.sgi.com/support/free/security/advisories/20020801-01-Phttp://archives.neohapsis.com/archives/aix/2002-q4/0002.htmlhttp://archives.neohapsis.com/archives/bugtraq/2002-07/0514.htmlhttp://archives.neohapsis.com/archives/hp/2002-q3/0077.htmlhttp://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20823http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000515http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000535http://marc.info/?l=bugtraq&m=102813809232532&w=2http://marc.info/?l=bugtraq&m=102821785316087&w=2http://marc.info/?l=bugtraq&m=102821928418261&w=2http://marc.info/?l=bugtraq&m=102831443208382&w=2http://marc.info/?l=bugtraq&m=103158632831416&w=2http://online.securityfocus.com/advisories/4402http://online.securityfocus.com/archive/1/285740http://rhn.redhat.com/errata/RHSA-2002-166.htmlhttp://rhn.redhat.com/errata/RHSA-2002-172.htmlhttp://www.cert.org/advisories/CA-2002-25.htmlhttp://www.debian.org/security/2002/dsa-142http://www.debian.org/security/2002/dsa-143http://www.debian.org/security/2002/dsa-146http://www.debian.org/security/2002/dsa-149http://www.debian.org/security/2003/dsa-333http://www.iss.net/security_center/static/9170.phphttp://www.kb.cert.org/vuls/id/192995http://www.linuxsecurity.com/advisories/other_advisory-2399.htmlhttp://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:057http://www.redhat.com/support/errata/RHSA-2002-167.htmlhttp://www.redhat.com/support/errata/RHSA-2002-173.htmlhttp://www.redhat.com/support/errata/RHSA-2003-168.htmlhttp://www.redhat.com/support/errata/RHSA-2003-212.htmlhttp://www.securityfocus.com/bid/5356https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-057https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A42https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4728https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9
2002-08-12
Published