CVE-2003-0028
Summary
| CVE | CVE-2003-0028 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-03-25 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Cray | Unicos | 6.0 | All | All | All |
| Operating System | Cray | Unicos | 6.0e | All | All | All |
| Operating System | Cray | Unicos | 6.1 | All | All | All |
| Operating System | Cray | Unicos | 7.0 | All | All | All |
| Operating System | Cray | Unicos | 8.0 | All | All | All |
| Operating System | Cray | Unicos | 8.3 | All | All | All |
| Operating System | Cray | Unicos | 9.0 | All | All | All |
| Operating System | Cray | Unicos | 9.0.2.5 | All | All | All |
| Operating System | Cray | Unicos | 9.2 | All | All | All |
| Operating System | Cray | Unicos | 9.2.4 | All | All | All |
| Operating System | Freebsd | Freebsd | 4.0 | All | All | All |
| Operating System | Freebsd | Freebsd | 4.1 | All | All | All |
| Operating System | Freebsd | Freebsd | 4.1.1 | All | All | All |
| Operating System | Freebsd | Freebsd | 4.1.1 | release | All | All |
| Operating System | Freebsd | Freebsd | 4.1.1 | stable | All | All |
| Operating System | Freebsd | Freebsd | 4.2 | All | All | All |
| Operating System | Freebsd | Freebsd | 4.2 | stable | All | All |
| Operating System | Freebsd | Freebsd | 4.3 | All | All | All |
| Operating System | Freebsd | Freebsd | 4.3 | release | All | All |
| Operating System | Freebsd | Freebsd | 4.3 | stable | All | All |
| Operating System | Freebsd | Freebsd | 4.4 | All | All | All |
| Operating System | Freebsd | Freebsd | 4.4 | stable | All | All |
| Operating System | Freebsd | Freebsd | 4.5 | All | All | All |
| Operating System | Freebsd | Freebsd | 4.5 | release | All | All |
| Operating System | Freebsd | Freebsd | 4.5 | stable | All | All |
| Operating System | Freebsd | Freebsd | 4.6 | All | All | All |
| Operating System | Freebsd | Freebsd | 4.6 | release | All | All |
| Operating System | Freebsd | Freebsd | 4.6 | stable | All | All |
| Operating System | Freebsd | Freebsd | 4.6.2 | All | All | All |
| Operating System | Freebsd | Freebsd | 4.7 | All | All | All |
| Operating System | Freebsd | Freebsd | 4.7 | release | All | All |
| Operating System | Freebsd | Freebsd | 4.7 | stable | All | All |
| Operating System | Freebsd | Freebsd | 5.0 | All | All | All |
| Application | Gnu | Glibc | 2.1 | All | All | All |
| Application | Gnu | Glibc | 2.1.1 | All | All | All |
| Application | Gnu | Glibc | 2.1.2 | All | All | All |
| Application | Gnu | Glibc | 2.1.3 | All | All | All |
| Application | Gnu | Glibc | 2.2 | All | All | All |
| Application | Gnu | Glibc | 2.2.1 | All | All | All |
| Application | Gnu | Glibc | 2.2.2 | All | All | All |
| Application | Gnu | Glibc | 2.2.3 | All | All | All |
| Application | Gnu | Glibc | 2.2.4 | All | All | All |
| Application | Gnu | Glibc | 2.2.5 | All | All | All |
| Application | Gnu | Glibc | 2.3 | All | All | All |
| Application | Gnu | Glibc | 2.3.1 | All | All | All |
| Application | Gnu | Glibc | 2.3.2 | All | All | All |
| Operating System | Hp | Hp-ux | 10.20 | All | All | All |
| Operating System | Hp | Hp-ux | 10.24 | All | All | All |
| Operating System | Hp | Hp-ux | 11.00 | All | All | All |
| Operating System | Hp | Hp-ux | 11.04 | All | All | All |
| Operating System | Hp | Hp-ux | 11.11 | All | All | All |
| Operating System | Hp | Hp-ux | 11.20 | All | All | All |
| Operating System | Hp | Hp-ux | 11.22 | All | All | All |
| Operating System | Hp | Hp-ux Series 700 | 10.20 | All | All | All |
| Operating System | Hp | Hp-ux Series 800 | 10.20 | All | All | All |
| Operating System | Ibm | Aix | 4.3.3 | All | All | All |
| Operating System | Ibm | Aix | 5.1 | All | All | All |
| Operating System | Ibm | Aix | 5.2 | All | All | All |
| Application | Mit | Kerberos 5 | 1.2 | All | All | All |
| Application | Mit | Kerberos 5 | 1.2.1 | All | All | All |
| Application | Mit | Kerberos 5 | 1.2.2 | All | All | All |
| Application | Mit | Kerberos 5 | 1.2.3 | All | All | All |
| Application | Mit | Kerberos 5 | 1.2.4 | All | All | All |
| Application | Mit | Kerberos 5 | 1.2.5 | All | All | All |
| Application | Mit | Kerberos 5 | 1.2.6 | All | All | All |
| Application | Mit | Kerberos 5 | 1.2.7 | All | All | All |
| Application | Openafs | Openafs | 1.0 | All | All | All |
| Application | Openafs | Openafs | 1.0.1 | All | All | All |
| Application | Openafs | Openafs | 1.0.2 | All | All | All |
| Application | Openafs | Openafs | 1.0.3 | All | All | All |
| Application | Openafs | Openafs | 1.0.4 | All | All | All |
| Application | Openafs | Openafs | 1.0.4a | All | All | All |
| Application | Openafs | Openafs | 1.1 | All | All | All |
| Application | Openafs | Openafs | 1.1.1 | All | All | All |
| Application | Openafs | Openafs | 1.1.1a | All | All | All |
| Application | Openafs | Openafs | 1.2 | All | All | All |
| Application | Openafs | Openafs | 1.2.1 | All | All | All |
| Application | Openafs | Openafs | 1.2.2 | All | All | All |
| Application | Openafs | Openafs | 1.2.2a | All | All | All |
| Application | Openafs | Openafs | 1.2.2b | All | All | All |
| Application | Openafs | Openafs | 1.2.3 | All | All | All |
| Application | Openafs | Openafs | 1.2.4 | All | All | All |
| Application | Openafs | Openafs | 1.2.5 | All | All | All |
| Application | Openafs | Openafs | 1.2.6 | All | All | All |
| Application | Openafs | Openafs | 1.3 | All | All | All |
| Application | Openafs | Openafs | 1.3.1 | All | All | All |
| Application | Openafs | Openafs | 1.3.2 | All | All | All |
| Operating System | Openbsd | Openbsd | 2.0 | All | All | All |
| Operating System | Openbsd | Openbsd | 2.1 | All | All | All |
| Operating System | Openbsd | Openbsd | 2.2 | All | All | All |
| Operating System | Openbsd | Openbsd | 2.3 | All | All | All |
| Operating System | Openbsd | Openbsd | 2.4 | All | All | All |
| Operating System | Openbsd | Openbsd | 2.5 | All | All | All |
| Operating System | Openbsd | Openbsd | 2.6 | All | All | All |
| Operating System | Openbsd | Openbsd | 2.7 | All | All | All |
| Operating System | Openbsd | Openbsd | 2.8 | All | All | All |
| Operating System | Openbsd | Openbsd | 2.9 | All | All | All |
| Operating System | Openbsd | Openbsd | 3.0 | All | All | All |
| Operating System | Openbsd | Openbsd | 3.1 | All | All | All |
| Operating System | Openbsd | Openbsd | 3.2 | All | All | All |
| Operating System | Sgi | Irix | 6.5 | All | All | All |
| Operating System | Sgi | Irix | 6.5.1 | All | All | All |
| Operating System | Sgi | Irix | 6.5.10 | All | All | All |
| Operating System | Sgi | Irix | 6.5.10f | All | All | All |
| Operating System | Sgi | Irix | 6.5.10m | All | All | All |
| Operating System | Sgi | Irix | 6.5.11 | All | All | All |
| Operating System | Sgi | Irix | 6.5.11f | All | All | All |
| Operating System | Sgi | Irix | 6.5.11m | All | All | All |
| Operating System | Sgi | Irix | 6.5.12 | All | All | All |
| Operating System | Sgi | Irix | 6.5.12f | All | All | All |
| Operating System | Sgi | Irix | 6.5.12m | All | All | All |
| Operating System | Sgi | Irix | 6.5.13 | All | All | All |
| Operating System | Sgi | Irix | 6.5.13f | All | All | All |
| Operating System | Sgi | Irix | 6.5.13m | All | All | All |
| Operating System | Sgi | Irix | 6.5.14 | All | All | All |
| Operating System | Sgi | Irix | 6.5.14f | All | All | All |
| Operating System | Sgi | Irix | 6.5.14m | All | All | All |
| Operating System | Sgi | Irix | 6.5.15 | All | All | All |
| Operating System | Sgi | Irix | 6.5.15f | All | All | All |
| Operating System | Sgi | Irix | 6.5.15m | All | All | All |
| Operating System | Sgi | Irix | 6.5.16 | All | All | All |
| Operating System | Sgi | Irix | 6.5.16f | All | All | All |
| Operating System | Sgi | Irix | 6.5.16m | All | All | All |
| Operating System | Sgi | Irix | 6.5.17 | All | All | All |
| Operating System | Sgi | Irix | 6.5.17f | All | All | All |
| Operating System | Sgi | Irix | 6.5.17m | All | All | All |
| Operating System | Sgi | Irix | 6.5.18 | All | All | All |
| Operating System | Sgi | Irix | 6.5.18f | All | All | All |
| Operating System | Sgi | Irix | 6.5.18m | All | All | All |
| Operating System | Sgi | Irix | 6.5.19 | All | All | All |
| Operating System | Sgi | Irix | 6.5.2 | All | All | All |
| Operating System | Sgi | Irix | 6.5.20 | All | All | All |
| Operating System | Sgi | Irix | 6.5.2f | All | All | All |
| Operating System | Sgi | Irix | 6.5.2m | All | All | All |
| Operating System | Sgi | Irix | 6.5.3 | All | All | All |
| Operating System | Sgi | Irix | 6.5.3f | All | All | All |
| Operating System | Sgi | Irix | 6.5.3m | All | All | All |
| Operating System | Sgi | Irix | 6.5.4 | All | All | All |
| Operating System | Sgi | Irix | 6.5.4f | All | All | All |
| Operating System | Sgi | Irix | 6.5.4m | All | All | All |
| Operating System | Sgi | Irix | 6.5.5 | All | All | All |
| Operating System | Sgi | Irix | 6.5.5f | All | All | All |
| Operating System | Sgi | Irix | 6.5.5m | All | All | All |
| Operating System | Sgi | Irix | 6.5.6 | All | All | All |
| Operating System | Sgi | Irix | 6.5.6f | All | All | All |
| Operating System | Sgi | Irix | 6.5.6m | All | All | All |
| Operating System | Sgi | Irix | 6.5.7 | All | All | All |
| Operating System | Sgi | Irix | 6.5.7f | All | All | All |
| Operating System | Sgi | Irix | 6.5.7m | All | All | All |
| Operating System | Sgi | Irix | 6.5.8 | All | All | All |
| Operating System | Sgi | Irix | 6.5.8f | All | All | All |
| Operating System | Sgi | Irix | 6.5.8m | All | All | All |
| Operating System | Sgi | Irix | 6.5.9 | All | All | All |
| Operating System | Sgi | Irix | 6.5.9f | All | All | All |
| Operating System | Sgi | Irix | 6.5.9m | All | All | All |
| Operating System | Sun | Solaris | 2.5.1 | All | x86 | All |
| Operating System | Sun | Solaris | 2.6 | All | All | All |
| Operating System | Sun | Solaris | 7.0 | All | x86 | All |
| Operating System | Sun | Solaris | 8.0 | All | x86 | All |
| Operating System | Sun | Solaris | 9.0 | All | sparc | All |
| Operating System | Sun | Solaris | 9.0 | All | x86 | All |
| Operating System | Sun | Sunos | - | All | All | All |
| Operating System | Sun | Sunos | 5.5.1 | All | All | All |
| Operating System | Sun | Sunos | 5.7 | All | All | All |
| Operating System | Sun | Sunos | 5.8 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| NOVELL: Broken Link - 404 Error Pages | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| Debian -- Security Information -- DSA-272-1 dietlibc | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| 'MITKRB5-SA-2003-003: faulty length checks in xdrmem_getbytes' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| '[slackware-security] glibc XDR overflow fix (SSA:2003-141-03)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-008.txt.asc | af854a3a-2127-422b-91ae-364da2661108 | ftp.netbsd.org | |
| 'TSLSA-2003-0014 - glibc' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Debian -- Security Information -- DSA-266-1 krb5 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| 'GLSA: glibc (200303-22)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| BeyondTrust | Privileged Access Management, Cyber Security, and Remote Access (formerly Bomgar) | BeyondTrust | af854a3a-2127-422b-91ae-364da2661108 | www.eeye.com | Exploit, Vendor Advisory |
| LinuxSecurity.com: EnGarde: 'glibc' RPC XDR decoder vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.linuxsecurity.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CERT Advisory CA-2003-10 Integer overflow in Sun RPC XDR library routines | af854a3a-2127-422b-91ae-364da2661108 | www.cert.org | Patch, Third Party Advisory, US Government Resource |
| Debian -- Security Information -- DSA-282-1 glibc | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| 'EEYE: XDR Integer Overflow' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Neohapsis Archives - VulnWatch - #0140 - [VulnWatch] EEYE: XDR Integer Overflow | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| CERT/CC Vulnerability Note VU#516825 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| CVE-2003-0028 XDR Libraries Integer Overflow Vulnerability in Data ONTAP | NetApp Product Security | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | |
| Advisories - Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.