VDB
DEBIAN-CVE-2003-0028
DEBIAN-CVE-2003-0028
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | krb5 | 0, 0, 0 |
| Debian:14 | dietlibc | 0, 0, 0 |
| Debian:12 | glibc | 0, 0, 0 |
| Debian:14 | glibc | 0, 0, 0 |
| Debian:11 | krb5 | 0, 0, 0 |
| Debian:13 | krb5 | 0, 0, 0 |
| Debian:13 | dietlibc | 0, 0, 0 |
| Debian:11 | glibc | 0, 0, 0 |
| Debian:12 | dietlibc | 0, 0, 0 |
| Debian:14 | krb5 | 0, 0, 0 |
| Debian:13 | glibc | 0, 0, 0 |
| Debian:11 | dietlibc | 0, 0, 0 |
Timeline
- Mar 25, 2003 CVE Published
- Apr 28, 2026 CVE Updated