CVE-2003-0028

Source
https://nvd.nist.gov/vuln/detail/CVE-2003-0028
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2003-0028.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2003-0028
Related
Published
2003-03-25T05:00:00Z
Modified
2024-11-20T23:43:46Z
Summary
[none]
Details

Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.

References

Affected packages

Debian:11 / dietlibc

Package

Name
dietlibc
Purl
pkg:deb/debian/dietlibc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.22-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / dietlibc

Package

Name
dietlibc
Purl
pkg:deb/debian/dietlibc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.22-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / dietlibc

Package

Name
dietlibc
Purl
pkg:deb/debian/dietlibc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.22-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:11 / glibc

Package

Name
glibc
Purl
pkg:deb/debian/glibc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.1-16

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / glibc

Package

Name
glibc
Purl
pkg:deb/debian/glibc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.1-16

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / glibc

Package

Name
glibc
Purl
pkg:deb/debian/glibc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.1-16

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:11 / krb5

Package

Name
krb5
Purl
pkg:deb/debian/krb5?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.3-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / krb5

Package

Name
krb5
Purl
pkg:deb/debian/krb5?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.3-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / krb5

Package

Name
krb5
Purl
pkg:deb/debian/krb5?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.3-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}