CVE-2002-1232
published 2002-11-04CVE-2002-1232: Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory…
PriorityP416medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.25%
86.9th percentile
Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | nis | < nis 3.9-6.2 (bookworm) | nis 3.9-6.2 (bookworm) |
| hp | secure_os | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xj67-5prp-p33j: Memory leak in ypdb_open in yp_db
ghsa_unreviewed·2022-05-03
CVE-2002-1232 [MEDIUM] GHSA-xj67-5prp-p33j: Memory leak in ypdb_open in yp_db
Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist.
OSV
CVE-2002-1232: Memory leak in ypdb_open in yp_db
osv·2002-11-04·CVSS 5.0
CVE-2002-1232 [MEDIUM] CVE-2002-1232: Memory leak in ypdb_open in yp_db
Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist.
Red Hat
security flaw
vendor_redhat·2002-10-21·CVSS 5.0
CVE-2002-1232 [MEDIUM] security flaw
security flaw
Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist.
Debian
CVE-2002-1232: nis - Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9...
vendor_debian·2002·CVSS 5.0
CVE-2002-1232 [MEDIUM] CVE-2002-1232: nis - Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9...
Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist.
Scope: local
bookworm: resolved (fixed in 3.9-6.2)
bullseye: resolved (fixed in 3.9-6.2)
forky: resolved (fixed in 3.9-6.2)
sid: resolved (fixed in 3.9-6.2)
trixie: resolved (fixed in 3.9-6.2)
Suricata
GPL RPC portmap ypserv request UDP
suricata·2010-09-23
CVE-2000-1042 GPL RPC portmap ypserv request UDP
GPL RPC portmap ypserv request UDP
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET 111 (msg:"GPL RPC portmap ypserv request UDP"; content:"|00 01 86 A0|"; depth:4; offset:12; content:"|00 00 00 03|"; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:"|00 01 86 A4|"; within:4; content:"|00 00 00 00|"; depth:4; offset:4; reference:arachnids,12; reference:bugtraq,5914; reference:bugtraq,6016; reference:cve,2000-1042; reference:cve,2000-1043; reference:cve,2002-1232; classtype:rpc-portmap-decode; sid:2100590; rev:13; metadata:created_at 2010_09_23, cve CVE_2000_1042, signature_severity Informational, updated_at 2019_07_26;)
Suricata
GPL RPC portmap ypserv request TCP
suricata·2010-09-23
CVE-2000-1042 GPL RPC portmap ypserv request TCP
GPL RPC portmap ypserv request TCP
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 111 (msg:"GPL RPC portmap ypserv request TCP"; flow:established,to_server; content:"|00 01 86 A0|"; depth:4; offset:16; content:"|00 00 00 03|"; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:"|00 01 86 A4|"; within:4; content:"|00 00 00 00|"; depth:4; offset:8; reference:arachnids,12; reference:bugtraq,5914; reference:bugtraq,6016; reference:cve,2000-1042; reference:cve,2000-1043; reference:cve,2002-1232; classtype:rpc-portmap-decode; sid:2101276; rev:16; metadata:created_at 2010_09_23, cve CVE_2000_1042, signature_severity Informational, updated_at 2024_03_08;)
No public exploits indexed.
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-054.0.txthttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000539http://marc.info/?l=bugtraq&m=103582692228894&w=2http://online.securityfocus.com/advisories/4605http://www.debian.org/security/2002/dsa-180http://www.iss.net/security_center/static/10423.phphttp://www.linux-mandrake.com/en/security/2002/MDKSA-2002-078.phphttp://www.redhat.com/support/errata/RHSA-2002-223.htmlhttp://www.redhat.com/support/errata/RHSA-2002-224.htmlhttp://www.redhat.com/support/errata/RHSA-2003-229.htmlhttp://www.securityfocus.com/bid/6016ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-054.0.txthttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000539http://marc.info/?l=bugtraq&m=103582692228894&w=2http://online.securityfocus.com/advisories/4605http://www.debian.org/security/2002/dsa-180http://www.iss.net/security_center/static/10423.phphttp://www.linux-mandrake.com/en/security/2002/MDKSA-2002-078.phphttp://www.redhat.com/support/errata/RHSA-2002-223.htmlhttp://www.redhat.com/support/errata/RHSA-2002-224.htmlhttp://www.redhat.com/support/errata/RHSA-2003-229.htmlhttp://www.securityfocus.com/bid/6016
2002-11-04
Published