VDB
CERTCC-2002-192995
CERTCC-2002-192995
PUBLISHED
There is an integer overflow present in the xdr_array() function distributed as part of the Sun Microsystems XDR library. This overflow has been shown to lead to remotely exploitable buffer overflows in multiple applications, leading to the execution of arbitrary code. Although the library was originally distributed by Sun Microsystems, multiple vendors have included the vulnerable code in their own implementations.
Timeline
- Jul 31, 2002 CVE Published
- May 15, 2006 CVE Updated
- Mar 17, 2026 Security Advisory
References
- Integer overflow in xdr_array() function when deserializing the XDR stream advisory
- Integer overflow in xdr_array() function when deserializing the XDR stream url
- Integer overflow in xdr_array() function when deserializing the XDR stream url
- Integer overflow in xdr_array() function when deserializing the XDR stream url
- Integer overflow in xdr_array() function when deserializing the XDR stream url
- Integer overflow in xdr_array() function when deserializing the XDR stream url
- Integer overflow in xdr_array() function when deserializing the XDR stream url
- Integer overflow in xdr_array() function when deserializing the XDR stream url
- Integer overflow in xdr_array() function when deserializing the XDR stream url
- Integer overflow in xdr_array() function when deserializing the XDR stream advisory