CVE-2002-0391
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
- Affected products
- Debian, Red Hat, Dietlibc, Glibc, Glibc-Common, Glibc-Devel, Glibc-Profile, Krb5
- Freebsd
- ≤ 4.6.1
- Openbsd
- = 3.1
- Sun Solaris
- = 2.6, 9.0
- Sun Sunos
- = 5.5.1, 5.7, 5.8
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 58.1% (99th percentile)
- Weakness
- CWE-190
- NVD status
- Modified
- Published
- 2003-04-02
CVE-2002-0391 at NVD
2 known exploits for CVE-2002-0391
Proof-of-concept code and exploit modules indexed by Sploitus