cbcvebase.
CVE-2002-0391
published 2002-08-12

CVE-2002-0391: Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows…

PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
58.13%
99.0th percentile
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.

Affected

172 ranges· showing 25
VendorProductVersion rangeFixed in
crayunicos
crayunicos
crayunicos
crayunicos
crayunicos
crayunicos
crayunicos
crayunicos
crayunicos
crayunicos
debianacm< acm 5.0-10 (bookworm)acm 5.0-10 (bookworm)
debiandietlibc< dietlibc 0.22-2 (bookworm)dietlibc 0.22-2 (bookworm)
debiandietlibc< acm 5.0-10 (bookworm)acm 5.0-10 (bookworm)
debianglibc< dietlibc 0.22-2 (bookworm)dietlibc 0.22-2 (bookworm)
debianglibc< acm 5.0-10 (bookworm)acm 5.0-10 (bookworm)
debiankrb5< dietlibc 0.22-2 (bookworm)dietlibc 0.22-2 (bookworm)
debiankrb5< acm 5.0-10 (bookworm)acm 5.0-10 (bookworm)
debianopenafs< acm 5.0-10 (bookworm)acm 5.0-10 (bookworm)
freebsdfreebsd<= 4.6.1
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd

Detection & IOCsextracted from sources · hover to see the quote

  • Target RPC services known to be exploitable via xdr_array integer overflow: rpc.cmsd and dmispd. Monitor for anomalous RPC calls to these services with unusually large argument counts.
  • The vulnerable function is xdr_array in SunRPC-derived libraries (libc, glibc, dietlibc). Inspect RPC traffic for integer overflow conditions triggered by excessively large array size fields in XDR-encoded requests.
  • ·Vulnerability affects multiple SunRPC-derived library implementations across different operating systems; scope of affected systems is broad.
  • ·Debian packages have resolved CVE-2002-0391 at version 5.0-10 across bookworm, bullseye, sid, and trixie; verify package versions when assessing exposure.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.