search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Multiple Sun RPC-based libc implementations fails to provide time-out mechanism when reading data from TCP connections

Vulnerability Note VU#266817

Original Release Date: 2002-11-04 | Last Revised: 2003-04-09

Overview

A denial-of-service vulnerability exists in multiple vendor Sun RPC-based libc implementations.

Description

Multiple vendor Sun RPC-based libc implementations fail to properly read data from TCP connections. As a result, a remote attacker can deny service to system daemons.

Impact

A remote attacker can connect to a vulnerable service and cause the service to hang.

Solution

Apply a vendor patch when available.

Vendor Information

266817
 

View all 29 vendors View less vendors


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This document was written by Ian A Finlay.

Other Information

CVE IDs: CVE-2002-1265
Severity Metric: 10.31
Date Public: 2002-11-04
Date First Published: 2002-11-04
Date Last Updated: 2003-04-09 19:10 UTC
Document Revision: 22

Sponsored by CISA.