Back

CVE-2003-0028

Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.

Published: Mar 25, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (165)

Vendor Product Version
gnu glibc 2.1
gnu glibc 2.1.1
gnu glibc 2.1.2
gnu glibc 2.1.3
gnu glibc 2.2
gnu glibc 2.2.1
gnu glibc 2.2.2
gnu glibc 2.2.3
gnu glibc 2.2.4
gnu glibc 2.2.5
gnu glibc 2.3
gnu glibc 2.3.1
gnu glibc 2.3.2
mit kerberos_5 1.2
mit kerberos_5 1.2.1
mit kerberos_5 1.2.2
mit kerberos_5 1.2.3
mit kerberos_5 1.2.4
mit kerberos_5 1.2.5
mit kerberos_5 1.2.6

…and 145 more

GitHub Security Advisory GHSA-235q-hvh2-g375

Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR ...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 15.03%

Top 4% most likely to be exploited

Threat Score 34.5 / 100

Data Sources

NVD EPSS GitHub