VDB
CVE-2002-1232
CVE-2002-1232
PUBLISHED
CVSS 5 MEDIUM
Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist.
EPSS 3.25% · 87.1th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
3.25%
87.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | linux | 7.1, 6.2, 6.2 |
| hp | secure_os | 1.0 |
| n/a | n/a | n/a |
| debian | debian_linux | 2.2, 2.2, 2.2 |
Timeline
- CVE Published
- Sep 23, 2010 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Aug 9, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- DSA-180 vendor-advisory
- RHSA-2002:224 vendor-advisory
- 6016 vdb
- 20021028 GLSA: ypserv mailing-list
- CSSA-2002-054.0 vendor-advisory
- MDKSA-2002:078 vendor-advisory
- CLA-2002:539 vendor-advisory
- http://online.securityfocus.com/advisories/4605 technical
- http://www.redhat.com/support/errata/RHSA-2002-223.html patch
- http://www.iss.net/security_center/static/10423.php advisory
- http://www.redhat.com/support/errata/RHSA-2003-229.html technical
- https://nvd.nist.gov/vuln/detail/CVE-2002-1232 advisory