cbcvebase.
CVE-2003-0028
published 2003-03-25

CVE-2003-0028: Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC…

PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
15.03%
96.3th percentile
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.

Affected

154 ranges· showing 25
VendorProductVersion rangeFixed in
crayunicos
crayunicos
crayunicos
crayunicos
crayunicos
crayunicos
crayunicos
crayunicos
crayunicos
crayunicos
debiandietlibc< dietlibc 0.22-2 (bookworm)dietlibc 0.22-2 (bookworm)
debianglibc< dietlibc 0.22-2 (bookworm)dietlibc 0.22-2 (bookworm)
debiankrb5< dietlibc 0.22-2 (bookworm)dietlibc 0.22-2 (bookworm)
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
gnuglibc

Detection & IOCsextracted from sources · hover to see the quote

port111/tcp
snort
alert tcp $EXTERNAL_NET any -> $HOME_NET 111 (msg:"GPL RPC portmap proxy integer overflow attempt TCP"; flow:established,to_server; content:"|00 01 86 A0 00|"; depth:5; offset:16; content:"|00 00 00 05|"; within:4; distance:3; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,>,2048,12,relative; content:"|00 00 00 00|"; depth:4; offset:8; reference:bugtraq,7123; reference:cve,2003-0028; classtype:rpc-portmap-decode; sid:2102093; rev:7; metadata:created_at 2010_09_23, cve CVE_2003_0028, confidence Medium, signature_severity Informational, updated_at 2024_03_08;)
bytes
|00 01 86 A0 00| at offset 16, depth 5
bytes
|00 00 00 05| within 4, distance 3 (after first content match)
bytes
|00 00 00 00| at offset 8, depth 4
  • Target TCP port 111 (RPC portmapper) for inbound connections from external networks; look for established flows to server matching the RPC portmap proxy integer overflow byte pattern.
  • Flag RPC requests where the byte_test detects a length field value greater than 2048 at relative offset 12, indicating a potential integer overflow in xdrmem_getbytes().
  • The vulnerability is triggered via certain integer values in XDR length fields sent to SunRPC-derived services (libnsl, libc, glibc, dietlibc); monitor RPC portmapper traffic for anomalously large length field values.
  • ·The Snort rule targets the RPC portmapper (port 111/TCP) specifically for the proxy integer overflow vector; other XDR-consuming services on different ports may also be vulnerable but are not covered by this rule.

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.