Sun XDR Library xdrmem_getbytes() Integer Overflow Vulnerability
BID:7123
Info
Sun XDR Library xdrmem_getbytes() Integer Overflow Vulnerability
| Bugtraq ID: | 7123 |
| Class: | Design Error |
| CVE: |
CVE-2003-0028 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Mar 17 2003 12:00AM |
| Updated: | Jul 11 2009 09:06PM |
| Credit: | The discovery of this vulnerability has been credited to Riley Hassell of eEye. |
| Vulnerable: |
Sun Solaris 2.5.1 _x86 Sun Solaris 2.5.1 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.6_x86 Sun Solaris 2.6 SGI IRIX 6.5.20 SGI IRIX 6.5.19 m SGI IRIX 6.5.19 f SGI IRIX 6.5.19 SGI IRIX 6.5.18 m SGI IRIX 6.5.18 f SGI IRIX 6.5.18 SGI IRIX 6.5.17 m SGI IRIX 6.5.17 f SGI IRIX 6.5.17 SGI IRIX 6.5.16 m SGI IRIX 6.5.16 f SGI IRIX 6.5.16 SGI IRIX 6.5.15 m SGI IRIX 6.5.15 f SGI IRIX 6.5.15 SGI IRIX 6.5.14 m SGI IRIX 6.5.14 f SGI IRIX 6.5.14 SGI IRIX 6.5.13 m SGI IRIX 6.5.13 f SGI IRIX 6.5.13 SGI IRIX 6.5.12 m SGI IRIX 6.5.12 f SGI IRIX 6.5.12 SGI IRIX 6.5.11 m SGI IRIX 6.5.11 f SGI IRIX 6.5.11 SGI IRIX 6.5.10 m SGI IRIX 6.5.10 f SGI IRIX 6.5.10 SGI IRIX 6.5.9 m SGI IRIX 6.5.9 f SGI IRIX 6.5.9 SGI IRIX 6.5.8 m SGI IRIX 6.5.8 f SGI IRIX 6.5.8 SGI IRIX 6.5.7 m SGI IRIX 6.5.7 f SGI IRIX 6.5.7 SGI IRIX 6.5.6 m SGI IRIX 6.5.6 f SGI IRIX 6.5.6 SGI IRIX 6.5.5 m SGI IRIX 6.5.5 f SGI IRIX 6.5.5 SGI IRIX 6.5.4 m SGI IRIX 6.5.4 f SGI IRIX 6.5.4 SGI IRIX 6.5.3 m SGI IRIX 6.5.3 f SGI IRIX 6.5.3 SGI IRIX 6.5.2 m SGI IRIX 6.5.2 f SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 OpenBSD OpenBSD 2.9 OpenBSD OpenBSD 2.8 OpenBSD OpenBSD 2.7 OpenBSD OpenBSD 2.6 OpenBSD OpenBSD 2.5 OpenBSD OpenBSD 2.4 OpenBSD OpenBSD 2.3 OpenBSD OpenBSD 2.2 OpenBSD OpenBSD 2.1 OpenBSD OpenBSD 2.0 OpenBSD OpenBSD 3.2 OpenBSD OpenBSD 3.1 OpenBSD OpenBSD 3.0 OpenAFS OpenAFS 1.3.2 OpenAFS OpenAFS 1.3.1 OpenAFS OpenAFS 1.3 OpenAFS OpenAFS 1.2.6 OpenAFS OpenAFS 1.2.5 OpenAFS OpenAFS 1.2.4 OpenAFS OpenAFS 1.2.3 OpenAFS OpenAFS 1.2.2 b OpenAFS OpenAFS 1.2.2 a OpenAFS OpenAFS 1.2.2 OpenAFS OpenAFS 1.2.1 OpenAFS OpenAFS 1.2 OpenAFS OpenAFS 1.1.1 a OpenAFS OpenAFS 1.1.1 OpenAFS OpenAFS 1.1 OpenAFS OpenAFS 1.0.4 a OpenAFS OpenAFS 1.0.4 OpenAFS OpenAFS 1.0.3 OpenAFS OpenAFS 1.0.2 OpenAFS OpenAFS 1.0.1 OpenAFS OpenAFS 1.0 NetBSD NetBSD 1.6 NetBSD NetBSD 1.5.3 NetBSD NetBSD 1.5.2 NetBSD NetBSD 1.5.1 NetBSD NetBSD 1.5 NetBSD NetBSD 1.4.3 NetBSD NetBSD 1.4.2 NetBSD NetBSD 1.4.1 NetBSD NetBSD 1.4 MIT Kerberos 5 1.2.7 MIT Kerberos 5 1.2.6 MIT Kerberos 5 1.2.5 MIT Kerberos 5 1.2.4 MIT Kerberos 5 1.2.3 MIT Kerberos 5 1.2.2 MIT Kerberos 5 1.2.1 MIT Kerberos 5 1.2 MIT Kerberos 5 1.1.1 IBM AIX 4.3.3 IBM AIX 5.2 IBM AIX 5.1 HP HP-UX 11.22 HP HP-UX 11.20 HP HP-UX 11.11 HP HP-UX 11.0 4 HP HP-UX 11.0 HP HP-UX 10.24 HP HP-UX 10.20 Series 800 HP HP-UX 10.20 Series 700 HP HP-UX 10.20 GNU glibc 2.3.2 GNU glibc 2.3.1 GNU glibc 2.3 GNU glibc 2.2.5 GNU glibc 2.2.4 GNU glibc 2.2.3 GNU glibc 2.2.2 GNU glibc 2.2.1 GNU glibc 2.2 GNU glibc 2.1.3 GNU glibc 2.1.2 GNU glibc 2.1.1 GNU glibc 2.1 FreeBSD FreeBSD 5.0 FreeBSD FreeBSD 4.7 -STABLE FreeBSD FreeBSD 4.7 -RELEASE FreeBSD FreeBSD 4.7 FreeBSD FreeBSD 4.6.2 FreeBSD FreeBSD 4.6 -STABLE FreeBSD FreeBSD 4.6 -RELEASE FreeBSD FreeBSD 4.6 FreeBSD FreeBSD 4.5 -STABLE FreeBSD FreeBSD 4.5 -RELEASE FreeBSD FreeBSD 4.5 FreeBSD FreeBSD 4.4 -STABLE FreeBSD FreeBSD 4.4 FreeBSD FreeBSD 4.3 -STABLE FreeBSD FreeBSD 4.3 -RELEASE FreeBSD FreeBSD 4.3 FreeBSD FreeBSD 4.2 -STABLE FreeBSD FreeBSD 4.2 -RELEASE FreeBSD FreeBSD 4.2 FreeBSD FreeBSD 4.1.1 -STABLE FreeBSD FreeBSD 4.1.1 -RELEASE FreeBSD FreeBSD 4.1.1 FreeBSD FreeBSD 4.1 FreeBSD FreeBSD 4.0 diet libc diet libc 0.19 diet libc diet libc 0.18 diet libc diet libc 0.17 diet libc diet libc 0.16 diet libc diet libc 0.15 diet libc diet libc 0.12 Cray UNICOS 9.2 .4 Cray UNICOS 9.2 Cray UNICOS 9.0.2 .5 Cray UNICOS 9.0 Cray UNICOS 8.3 Cray UNICOS 8.0 Cray UNICOS 7.0 Cray UNICOS 6.1 Cray UNICOS 6.0 E Cray UNICOS 6.0 Caldera OpenLinux Workstation 3.1.1 Caldera OpenLinux Workstation 3.1 Caldera OpenLinux Server 3.1.1 Caldera OpenLinux Server 3.1 Apple Mac OS X 10.2.4 Apple Mac OS X 10.2.3 Apple Mac OS X 10.2.2 Apple Mac OS X 10.2.1 Apple Mac OS X 10.2 Apple Mac OS X 10.1.5 Apple Mac OS X 10.1.4 Apple Mac OS X 10.1.3 Apple Mac OS X 10.1.2 Apple Mac OS X 10.1.1 Apple Mac OS X 10.1 Apple Mac OS X 10.1 Apple Mac OS X 10.0.4 Apple Mac OS X 10.0.3 Apple Mac OS X 10.0.2 Apple Mac OS X 10.0.1 Apple Mac OS X 10.0 |
| Not Vulnerable: |
NetBSD NetBSD 1.6.1 NetBSD NetBSD 1.6 NetBSD NetBSD 1.5.3 NetBSD NetBSD 1.5.2 NetBSD NetBSD 1.5.1 NetBSD NetBSD 1.5 NetBSD NetBSD 1.4.3 NetBSD NetBSD 1.4.2 NetBSD NetBSD 1.4.1 NetBSD NetBSD 1.4 NetBSD NetBSD 1.3.3 NetBSD NetBSD 1.3.2 NetBSD NetBSD 1.3.1 NetBSD NetBSD 1.3 NetBSD NetBSD 1.2.1 NetBSD NetBSD 1.2 NetBSD NetBSD 1.1 NetBSD NetBSD 1.0 Apple Mac OS X Server 10.2.4 Apple Mac OS X Server 10.2.3 Apple Mac OS X Server 10.2.2 Apple Mac OS X Server 10.2.1 Apple Mac OS X Server 10.2 Apple Mac OS X Server 10.0 Apple Mac OS X 10.2.4 Apple Mac OS X 10.2.3 Apple Mac OS X 10.2.2 Apple Mac OS X 10.2.1 Apple Mac OS X 10.2 Apple Mac OS X 10.1.5 Apple Mac OS X 10.1.4 Apple Mac OS X 10.1.3 Apple Mac OS X 10.1.2 Apple Mac OS X 10.1.1 Apple Mac OS X 10.1 Apple Mac OS X 10.1 Apple Mac OS X 10.0.4 Apple Mac OS X 10.0.3 Apple Mac OS X 10.0.2 Apple Mac OS X 10.0.1 Apple Mac OS X 10.0 |
Discussion
Sun XDR Library xdrmem_getbytes() Integer Overflow Vulnerability
A vulnerability has been discovered in the Sun XDR library. Specifically, an integer overflow as been found in the xdrmem_getbytes() function. As a result, applications implementing the vulnerable library call may be prone to denial of service attacks.
It should be noted that the vulnerable library code has been implemented by various libraries including BSD's libc, Glibc, and Sun Microsystem's libnsl.
A vulnerability has been discovered in the Sun XDR library. Specifically, an integer overflow as been found in the xdrmem_getbytes() function. As a result, applications implementing the vulnerable library call may be prone to denial of service attacks.
It should be noted that the vulnerable library code has been implemented by various libraries including BSD's libc, Glibc, and Sun Microsystem's libnsl.
Exploit / POC
Sun XDR Library xdrmem_getbytes() Integer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Sun XDR Library xdrmem_getbytes() Integer Overflow Vulnerability
Solution:
Conectiva has released a security advisory (CLA-2003:633). The referenced advisory contains information pertaining to obtaining and applying fixes that address this issue. Users are advised to upgrade as soon as possible.
Sorcerer Linux has advised that users update using the following commands:
augur synch && augur update
MIT has released a security advisory (2003-03-18) which contains a patch for KRB5 1.2.7.
Red Hat has released a security advisory (RHSA-2003:089-00) which contains fixes addressing this issue.
CERT has released a security advisory (CA-2003-10) which contains various vendor status information. Further details are available in the attached advisory.
The glibc 2.3.1 CVS tree has been updated to contain the necessary fixes. Further information can be found the in the attached CERT advisory.
It has been reported that IBM has released APAR IY38524, IY38434, IY39231, for AIX 4.3.3, 5.1, and 5.2 respectively. Users are advised to contact IBM support for further assistance.
FreeBSD has released an advisory (FreeBSD-SA-03:05) containing patches for version 4.6, 4.7, and 5.0. Users are advised to upgrade as soon as possible.
EnGarde has released a security advisory (ESA-20030321-010) containing a fix for this issue.
Debian has released a security advisory [DSA 266-1] containing fixes for this issue.
Debian has also released an advisory and fixes for dietlibc. See the References section for details.
Gentoo has released glibc-2.3.1-r4 (arm: glibc-2.2.5-r8) which addresses this issue. Users are advised to upgrade by performing the following commands:
emerge sync
emerge glibc
emerge clean
Gentoo has also released dietlibc-0.22-r1 which addresses this issue. Users are advised to upgrade by performing the following commands:
emerge sync
emerge dietlibc
emerge clean
MandrakeSoft has released an advisory (MDKSA-2003:037), which contain fixes for glibc. Further information about obtaining and applying fixes are available in the referenced advisory.
NetBSD has released a security advisory (2003-008) which contains information about obtaining fixes via CVS. Further information is available from the attached advisory.
Trustix has released a security advisory (TSLSA-2003-0014) which contains fixes addressing this issue. Users are advised to upgrade as soon as possible.
SGI has released a security advisory (20030402-01-P) which contains fixes addressing this issue.
Debian has released a new advisory (DSA 282-1) for glibc. Affected users are advised to obtain and install new packages. Further information is available in the referenced advisory. Users of the apt-get system can issue the following commands to install new packages:
apt-get update
apt-get upgrade
Conectiva has released a security advisory (CLA-2003:639) containing fixes which address this issue. Users are advised to upgrade as soon as possible.
Red Hat has released a new security advisory (RHSA-2003-090) containing fixes to address this issue. Fixes are available via the Red Hat Network. Further information can be obtained via the attached advisory or by contacting the vendor.
SuSE has released advisory SuSE-SA:2003:027 to address this issue.
Revised HP advisory HPSBUX0303-252 SSRT2439 Rev.11 is has been released to address this issue.
Fixes available:
Sun Solaris 8_sparc
Sun Solaris 7.0
diet libc diet libc 0.12
MIT Kerberos 5 1.1.1
MIT Kerberos 5 1.2.5
HP HP-UX 10.20
GNU glibc 2.2
FreeBSD FreeBSD 4.6
FreeBSD FreeBSD 5.0
SGI IRIX 6.5.15 m
SGI IRIX 6.5.16 f
SGI IRIX 6.5.16 m
SGI IRIX 6.5.17 m
SGI IRIX 6.5.19 f
Solution:
Conectiva has released a security advisory (CLA-2003:633). The referenced advisory contains information pertaining to obtaining and applying fixes that address this issue. Users are advised to upgrade as soon as possible.
Sorcerer Linux has advised that users update using the following commands:
augur synch && augur update
MIT has released a security advisory (2003-03-18) which contains a patch for KRB5 1.2.7.
Red Hat has released a security advisory (RHSA-2003:089-00) which contains fixes addressing this issue.
CERT has released a security advisory (CA-2003-10) which contains various vendor status information. Further details are available in the attached advisory.
The glibc 2.3.1 CVS tree has been updated to contain the necessary fixes. Further information can be found the in the attached CERT advisory.
It has been reported that IBM has released APAR IY38524, IY38434, IY39231, for AIX 4.3.3, 5.1, and 5.2 respectively. Users are advised to contact IBM support for further assistance.
FreeBSD has released an advisory (FreeBSD-SA-03:05) containing patches for version 4.6, 4.7, and 5.0. Users are advised to upgrade as soon as possible.
EnGarde has released a security advisory (ESA-20030321-010) containing a fix for this issue.
Debian has released a security advisory [DSA 266-1] containing fixes for this issue.
Debian has also released an advisory and fixes for dietlibc. See the References section for details.
Gentoo has released glibc-2.3.1-r4 (arm: glibc-2.2.5-r8) which addresses this issue. Users are advised to upgrade by performing the following commands:
emerge sync
emerge glibc
emerge clean
Gentoo has also released dietlibc-0.22-r1 which addresses this issue. Users are advised to upgrade by performing the following commands:
emerge sync
emerge dietlibc
emerge clean
MandrakeSoft has released an advisory (MDKSA-2003:037), which contain fixes for glibc. Further information about obtaining and applying fixes are available in the referenced advisory.
NetBSD has released a security advisory (2003-008) which contains information about obtaining fixes via CVS. Further information is available from the attached advisory.
Trustix has released a security advisory (TSLSA-2003-0014) which contains fixes addressing this issue. Users are advised to upgrade as soon as possible.
SGI has released a security advisory (20030402-01-P) which contains fixes addressing this issue.
Debian has released a new advisory (DSA 282-1) for glibc. Affected users are advised to obtain and install new packages. Further information is available in the referenced advisory. Users of the apt-get system can issue the following commands to install new packages:
apt-get update
apt-get upgrade
Conectiva has released a security advisory (CLA-2003:639) containing fixes which address this issue. Users are advised to upgrade as soon as possible.
Red Hat has released a new security advisory (RHSA-2003-090) containing fixes to address this issue. Fixes are available via the Red Hat Network. Further information can be obtained via the attached advisory or by contacting the vendor.
SuSE has released advisory SuSE-SA:2003:027 to address this issue.
Revised HP advisory HPSBUX0303-252 SSRT2439 Rev.11 is has been released to address this issue.
Fixes available:
Sun Solaris 8_sparc
-
Sun T108993-18
http://sunsolve.sun.com -
Sun 108993-18
SPARC Platform
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=108993&rev=18
Sun Solaris 7.0
-
Sun T106942-27
http://sunsolve.sun.com -
Sun 106942-27
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=106942&rev=27
diet libc diet libc 0.12
-
Debian dietlibc-dev_0.12-2.5_alpha.deb
http://security.debian.org/pool/updates/main/d/dietlibc/dietlibc-dev_0 .12-2.5_alpha.deb -
Debian dietlibc-dev_0.12-2.5_arm.deb
http://security.debian.org/pool/updates/main/d/dietlibc/dietlibc-dev_0 .12-2.5_arm.deb -
Debian dietlibc-dev_0.12-2.5_i386.deb
http://security.debian.org/pool/updates/main/d/dietlibc/dietlibc-dev_0 .12-2.5_i386.deb -
Debian dietlibc-dev_0.12-2.5_mips.deb
http://security.debian.org/pool/updates/main/d/dietlibc/dietlibc-dev_0 .12-2.5_mips.deb -
Debian dietlibc-dev_0.12-2.5_mipsel.deb
http://security.debian.org/pool/updates/main/d/dietlibc/dietlibc-dev_0 .12-2.5_mipsel.deb -
Debian dietlibc-dev_0.12-2.5_powerpc.deb
http://security.debian.org/pool/updates/main/d/dietlibc/dietlibc-dev_0 .12-2.5_powerpc.deb -
Debian dietlibc-dev_0.12-2.5_sparc.deb
http://security.debian.org/pool/updates/main/d/dietlibc/dietlibc-dev_0 .12-2.5_sparc.deb -
Debian dietlibc-doc_0.12-2.5_all.deb
http://security.debian.org/pool/updates/main/d/dietlibc/dietlibc-doc_0 .12-2.5_all.deb
MIT Kerberos 5 1.1.1
-
Red Hat krb5-configs-1.1.1-40.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/krb5-configs-1.1.1-40.i386.rpm -
Red Hat krb5-devel-1.1.1-40.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/krb5-devel-1.1.1-40.i386.rpm -
Red Hat krb5-libs-1.1.1-40.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/krb5-libs-1.1.1-40.i386.rpm -
Red Hat krb5-server-1.1.1-40.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/krb5-server-1.1.1-40.i386.rpm -
Red Hat krb5-workstation-1.1.1-40.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/krb5-workstation-1.1.1-40.i386 .rpm
MIT Kerberos 5 1.2.5
-
Immunix krb5-devel-1.2.5-1_imnx_1.i386.rpm
http://download.immunix.org/ImmunixOS/7+/Updates/RPMS/krb5-devel-1.2.5 -1_imnx_1.i386.rpm -
Immunix krb5-libs-1.2.5-1_imnx_1.i386.rpm
http://download.immunix.org/ImmunixOS/7+/Updates/RPMS/krb5-libs-1.2.5- 1_imnx_1.i386.rpm -
Immunix krb5-server-1.2.5-1_imnx_1.i386.rpm
http://download.immunix.org/ImmunixOS/7+/Updates/RPMS/krb5-server-1.2. 5-1_imnx_1.i386.rpm -
Immunix krb5-workstation-1.2.5-1_imnx_1.i386.rpm
http://download.immunix.org/ImmunixOS/7+/Updates/RPMS/krb5-workstation -1.2.5-1_imnx_1.i386.rpm -
MandrakeSoft ftp-client-krb5-1.2.5-1.4mdk.i586.rpm
Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft ftp-client-krb5-1.2.5-1.4mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft ftp-server-krb5-1.2.5-1.4mdk.i586.rpm
Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft ftp-server-krb5-1.2.5-1.4mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft krb5-devel-1.2.5-1.4mdk.i586.rpm
Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft krb5-devel-1.2.5-1.4mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft krb5-libs-1.2.5-1.4mdk.i586.rpm
Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft krb5-libs-1.2.5-1.4mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft krb5-server-1.2.5-1.4mdk.i586.rpm
Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft krb5-server-1.2.5-1.4mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft krb5-workstation-1.2.5-1.4mdk.i586.rpm
Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft krb5-workstation-1.2.5-1.4mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft telnet-client-krb5-1.2.5-1.4mdk.i586.rpm
Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft telnet-client-krb5-1.2.5-1.4mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft telnet-server-krb5-1.2.5-1.4mdk.i586.rpm
Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft telnet-server-krb5-1.2.5-1.4mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
Red Hat krb5-devel-1.2.5-15.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/krb5-devel-1.2.5-15.i386.rpm -
Red Hat krb5-libs-1.2.5-15.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/krb5-libs-1.2.5-15.i386.rpm -
Red Hat krb5-server-1.2.5-15.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/krb5-server-1.2.5-15.i386.rpm -
Red Hat krb5-workstation-1.2.5-15.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/krb5-workstation-1.2.5-15.i386 .rpm
HP HP-UX 10.20
-
HP PHCO_26158
http://itrc.hp.com
GNU glibc 2.2
-
Immunix glibc-2.2-12_imnx_28.i386.rpm
http://download.immunix.org/ImmunixOS/7+/Updates/RPMS/glibc-2.2-12_imn x_28.i386.rpm -
Immunix glibc-common-2.2-12_imnx_28.i386.rpm
http://download.immunix.org/ImmunixOS/7+/Updates/RPMS/glibc-common-2.2 -12_imnx_28.i386.rpm -
Immunix glibc-devel-2.2-12_imnx_28.i386.rpm
http://download.immunix.org/ImmunixOS/7+/Updates/RPMS/glibc-devel-2.2- 12_imnx_28.i386.rpm -
Immunix glibc-profile-2.2-12_imnx_28.i386.rpm
http://download.immunix.org/ImmunixOS/7+/Updates/RPMS/glibc-profile-2. 2-12_imnx_28.i386.rpm -
Immunix glibc-sdprofiles-2.2-12_imnx_28.i386.rpm
http://download.immunix.org/ImmunixOS/7+/Updates/RPMS/glibc-sdprofiles -2.2-12_imnx_28.i386.rpm -
SuSE glibc-2.2-26.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.1/a1/glibc-2.2-26.i386.rpm -
SuSE glibc-2.2-34.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.1/a1/glibc-2.2-34.alpha.rpm
FreeBSD FreeBSD 4.6
-
FreeBSD xdr-4.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:05/xdr-4.patch
FreeBSD FreeBSD 5.0
-
FreeBSD xdr-5.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:05/xdr-5.patch
SGI IRIX 6.5.15 m
SGI IRIX 6.5.16 f
SGI IRIX 6.5.16 m
SGI IRIX 6.5.17 m
SGI IRIX 6.5.19 f
References
Sun XDR Library xdrmem_getbytes() Integer Overflow Vulnerability
References:
References:
- 51884 (Sun Microsystems)
- RHSA-2003-090 (Red Hat)
- [Sorcerer-spells] GLIBC-SORCERER2003-03-20 (Michael Walton
) - [Sorcerer-spells] KRB5-SORCERER2003-03-20 (Michael Walton
) - MITKRB5-SA-2003-003: faulty length checks in xdrmem_getbytes (Tom Yu
) - RE: EEYE: XDR Integer Overflow ("Sinan Eren"
)