Back
CVE-2003-0028
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
Published: Mar 25, 2003
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (165)
| Vendor | Product | Version |
|---|---|---|
| gnu | glibc | 2.1 |
| gnu | glibc | 2.1.1 |
| gnu | glibc | 2.1.2 |
| gnu | glibc | 2.1.3 |
| gnu | glibc | 2.2 |
| gnu | glibc | 2.2.1 |
| gnu | glibc | 2.2.2 |
| gnu | glibc | 2.2.3 |
| gnu | glibc | 2.2.4 |
| gnu | glibc | 2.2.5 |
| gnu | glibc | 2.3 |
| gnu | glibc | 2.3.1 |
| gnu | glibc | 2.3.2 |
| mit | kerberos_5 | 1.2 |
| mit | kerberos_5 | 1.2.1 |
| mit | kerberos_5 | 1.2.2 |
| mit | kerberos_5 | 1.2.3 |
| mit | kerberos_5 | 1.2.4 |
| mit | kerberos_5 | 1.2.5 |
| mit | kerberos_5 | 1.2.6 |
…and 145 more
GitHub Security Advisory GHSA-235q-hvh2-g375
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR ...
References (50)
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-008.txt.asc
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0140.html
- http://marc.info/?l=bugtraq&m=104810574423662&w=2
- http://marc.info/?l=bugtraq&m=104811415301340&w=2
- http://marc.info/?l=bugtraq&m=104860855114117&w=2
- http://marc.info/?l=bugtraq&m=104878237121402&w=2
- http://marc.info/?l=bugtraq&m=105362148313082&w=2
- http://www.cert.org/advisories/CA-2003-10.html Patch, Third Party Advisory, US Government Resource
- http://www.debian.org/security/2003/dsa-266
- http://www.debian.org/security/2003/dsa-272
- http://www.debian.org/security/2003/dsa-282
- http://www.eeye.com/html/Research/Advisories/AD20030318.html Exploit, Vendor Advisory
- http://www.kb.cert.org/vuls/id/516825 US Government Resource
- http://www.linuxsecurity.com/advisories/engarde_advisory-3024.html
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:037
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
15.03%
Top 4% most likely to be exploited
Threat Score
34.5 / 100
Data Sources
NVD
EPSS
GitHub