CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2002-0391

CVSS 9.8v3.1pub. 2002-08-12upd. 2026-04-16

Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Freebsd

    OS
    Freebsd
    ≤ 4.6.1
  • Microsoft Windows 2000

    OS
    Microsoft
    all versions
  • Microsoft Windows Nt

    OS
    Microsoft
    4.0
  • Microsoft Windows Xp

    OS
    Microsoft
    all versions
  • Openbsd

    OS
    Openbsd
    3.1
  • Sun Solaris

    OS
    Sun
    2.69.0
  • Sun Sunos

    OS
    Sun
    5.5.15.75.8
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2014-1776CRITICAL9.8⚠ KEVPL ✓same product

Use-after-free w Microsoft Internet Explorer 6–11 umożliwia RCE

CVE-2008-4250CRITICAL9.8⚠ KEVPL ✓same product

RCE w usłudze Server systemu Windows przez przepełnienie bufora w RPC

CVE-2026-58081CRITICAL9.8same product

Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-sup...

CVE-2026-58082CRITICAL9.8same product

The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate character outp...

CVE-2024-10934CRITICAL9.2PL ✓same product

Double free i niezainicjowana zmienna w implementacji NFS systemu OpenBSD