PT-2001-2673 · Gnu+4 · Glibc-Devel+14

Published

1970-01-01

·

Updated

2025-01-16

·

CVE-2002-0391

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions krb5-workstation versions 1.1.1 through 1.2.2 krb5-devel versions 1.1.1 through 1.2.2 krb5-configs version 1.1.1 krb5-server versions 1.1.1 through 1.2.2 krb5-libs version 1.1.1 krb5 version 1.1.1 through 1.2.2 glibc versions 2.1.3 through 2.2.4 glibc-common version 2.2.4 glibc-profile versions 2.1.3 through 2.2.4 glibc-devel versions 2.1.3 through 2.2.4 acm (affected versions not specified) libnss1-compat (affected versions not specified)
Description The issue affects multiple packages in Red Hat Linux and Debian GNU/Linux operating systems, potentially leading to confidentiality, integrity, and availability breaches of protected information. Exploitation can be done remotely. Specifically, an integer overflow in the xdr array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC, including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr array through RPC services such as rpc.cmsd and dmispd.
Recommendations For krb5-workstation versions 1.1.1 through 1.2.2, update to a version that includes the fix for this issue. For krb5-devel versions 1.1.1 through 1.2.2, update to a version that includes the fix for this issue. For krb5-configs version 1.1.1, update to a version that includes the fix for this issue. For krb5-server versions 1.1.1 through 1.2.2, update to a version that includes the fix for this issue. For krb5-libs version 1.1.1, update to a version that includes the fix for this issue. For krb5 versions 1.1.1 through 1.2.2, update to a version that includes the fix for this issue. For glibc versions 2.1.3 through 2.2.4, update to a version that includes the fix for this issue. For glibc-common version 2.2.4, update to a version that includes the fix for this issue. For glibc-profile versions 2.1.3 through 2.2.4, update to a version that includes the fix for this issue. For glibc-devel versions 2.1.3 through 2.2.4, update to a version that includes the fix for this issue. For acm, at the moment, there is no information about a newer version that contains a fix for this issue. For libnss1-compat, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2015-02178
BDU:2015-02971
BDU:2015-07993
BDU:2015-07994
BDU:2015-07997
BDU:2015-08004
BDU:2015-08005
BDU:2015-08008
BDU:2015-08009
BDU:2015-08132
BDU:2015-08133
BDU:2015-08135
BDU:2015-08136
BDU:2015-08137
BDU:2015-08139
BDU:2015-08142
BDU:2015-08143
BDU:2015-08145
BDU:2015-08146
CVE-2002-0391
DSA-142
DSA-143
DSA-146
DSA-149
DSA-333

Affected Products

Debian
Red Hat
Dietlibc
Glibc
Glibc-Common
Glibc-Devel
Glibc-Profile
Krb5
Krb5-Configs
Krb5-Devel
Krb5-Libs
Krb5-Server
Krb5-Workstation
Libc
Libnss1-Compat