CVE-2002-1232Missing Release of Memory after Effective Lifetime in Linux

9 documents8 sources
Severity
5.0MEDIUMNVD
EPSS
6.0%
top 9.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 4
Latest updateMay 3

Description

Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDhp/secure_os1.0
NVDredhat/linux5 versions+4

Also affects: Debian Linux 2.2, 3.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-xj67-5prp-p33j: Memory leak in ypdb_open in yp_db2022-05-03
CVEList
CVE-2002-1232: Memory leak in ypdb_open in yp_db2004-09-01
OSV
CVE-2002-1232: Memory leak in ypdb_open in yp_db2002-11-04

🔍Detection Rules

2
Suricata
GPL RPC portmap ypserv request UDP2010-09-23
Suricata
GPL RPC portmap ypserv request TCP2010-09-23

📋Vendor Advisories

2
Red Hat
security flaw2002-10-21
Debian
CVE-2002-1232: nis - Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9...2002

💬Community

1
Bugzilla
CVE-2002-1232 security flaw2018-08-16
CVE-2002-1232 — Debian Linux vulnerability | cvebase