Vulnerability Note VU#266817
Multiple Sun RPC-based libc implementations fails to provide time-out mechanism when reading data from TCP connections
Overview
A denial-of-service vulnerability exists in multiple vendor Sun RPC-based libc implementations.
Description
Multiple vendor Sun RPC-based libc implementations fail to properly read data from TCP connections. As a result, a remote attacker can deny service to system daemons. |
Impact
A remote attacker can connect to a vulnerable service and cause the service to hang. |
Solution
Apply a vendor patch when available. |
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Apple Computer Inc. | Affected | 07 Oct 2002 | 18 Nov 2002 |
| GNU glibc | Affected | - | 04 Nov 2002 |
| IBM | Affected | 07 Oct 2002 | 15 Jan 2003 |
| SGI | Affected | - | 08 Nov 2002 |
| Sun Microsystems Inc. | Affected | 07 Oct 2002 | 28 Jan 2003 |
| BSDI | Unknown | 07 Oct 2002 | 08 Oct 2002 |
| Conectiva | Unknown | 07 Oct 2002 | 07 Oct 2002 |
| Cray Inc. | Unknown | 07 Oct 2002 | 30 Oct 2002 |
| Data General | Unknown | 07 Oct 2002 | 07 Oct 2002 |
| Debian | Unknown | 07 Oct 2002 | 14 Oct 2002 |
| Engarde | Unknown | 07 Oct 2002 | 08 Oct 2002 |
| FreeBSD | Unknown | 07 Oct 2002 | 08 Oct 2002 |
| Fujitsu | Unknown | 07 Oct 2002 | 08 Oct 2002 |
| Hewlett-Packard Company | Unknown | 07 Oct 2002 | 14 Oct 2002 |
| MandrakeSoft | Unknown | 07 Oct 2002 | 08 Oct 2002 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
Credit
This document was written by Ian A Finlay.
Other Information
- CVE IDs: CAN-2002-1265
- Date Public: 04 Nov 2002
- Date First Published: 04 Nov 2002
- Date Last Updated: 09 Apr 2003
- Severity Metric: 10.31
- Document Revision: 21
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.