IBM Corporation Information for VU#192995
Integer overflow in xdr_array() function when deserializing the XDR stream
- Vendor Information Help Date Notified: 29 Jul 2002
- Statement Date:
- Date Updated: 03 Sep 2002
IBM is vulnerable to the above XDR Library issues in both the 4.3 and 5.1 releases of AIX. A temporary patch is currently available through an efix pacakge. Efixes are available from
AIX 4.3.3: APAR #IY34194 ( available approx 10/1/2002 )
AIX 5.1.0: APAR #IY34158 ( available approx 10/16/2002 )
The vendor has not provided us with any further information regarding this vulnerability.
Previously on 08/06/2002 IBM stated:
IBM has analyzed AIX with regard to the XDR vulnerability and found that the 4.3.3 and 5.1.0 releases are exposed. We are currently working on an efix package for this issue which will be available shortly.
We will update this statement when more information once the efixes are available.
If you have feedback, comments, or additional information about this vulnerability, please send us email.