[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249982

 
 

909

 
 

195748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2003-0028Date: (C)2003-03-25   (M)2023-12-22


Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
2003-0014
http://marc.info/?l=bugtraq&m=104810574423662&w=2
http://marc.info/?l=bugtraq&m=104811415301340&w=2
http://www.securityfocus.com/archive/1/315638/30/25430/threaded
http://marc.info/?l=bugtraq&m=104860855114117&w=2
http://www.securityfocus.com/archive/1/316931/30/25250/threaded
http://www.securityfocus.com/archive/1/316960/30/25250/threaded
http://marc.info/?l=bugtraq&m=105362148313082&w=2
AD20030318
CA-2003-10
DSA-266
DSA-272
DSA-282
ESA-20030321-010
MDKSA-2003:037
NetBSD-SA2003-008
RHSA-2003:051
RHSA-2003:052
RHSA-2003:089
RHSA-2003:091
SuSE-SA:2003:027
VU#516825
https://security.netapp.com/advisory/ntap-20150122-0002/
oval:org.mitre.oval:def:230

CPE    118
cpe:/o:cray:unicos:8.0
cpe:/o:sgi:irix:6.5.13f
cpe:/o:sgi:irix:6.5.9m
cpe:/o:cray:unicos:8.3
...

© SecPod Technologies