CVE-2003-0028
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
- Affected products
- Red Hat, Glibc, Glibc-Common, Glibc-Devel, Glibc-Profile, Krb5, Krb5-Devel, Krb5-Libs
- Gnu Glibc
- = 2.1, 2.1.1, 2.1.2, 2.1.3, 2.2, 2.2.1, 2.2.2, 2.2.3, 2.2.4, 2.2.5, 2.3, 2.3.1, 2.3.2
- Mit Kerberos 5
- = 1.2, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7
- Openafs
- = 1.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.4a, 1.1, 1.1.1, 1.1.1a, 1.2, 1.2.1, 1.2.2, 1.2.2a, 1.2.2b, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.3
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 15.0% (96th percentile)
- NVD status
- Modified
- Published
- 2003-03-21
CVE-2003-0028 at NVD
No indexed exploits for CVE-2003-0028 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2003-0028 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.