CVE-2002-0391

CRITICAL

Freebsd < 4.6.1 - Integer Overflow

Title source: rule

Description

Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.

References (38)

... and 18 more

Scores

CVSS v3 9.8
EPSS 0.0826
EPSS Percentile 92.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-190
Status draft

Affected Products (10)

freebsd/freebsd < 4.6.1
openbsd/openbsd
sun/solaris
sun/solaris
sun/sunos
sun/sunos
sun/sunos
microsoft/windows_2000
microsoft/windows_nt
microsoft/windows_xp

Timeline

Published Aug 12, 2002
Tracked Since Feb 18, 2026