First published: Sat Aug 31 2002(Updated: )
Multiple format string vulnerabilities in in.rarpd (ARP server) on Solaris, Caldera UnixWare and Open UNIX, and possibly other operating systems, allows remote attackers to execute arbitrary code via format strings that are not properly handled in the functions (1) syserr and (2) error.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xinuos UnixWare | =7.1.1 | |
SunOS | =5.7 | |
SunOS | =5.8 | |
SCO Open UNIX | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0884 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary code.
To mitigate CVE-2002-0884, it is recommended to patch the affected systems or disable the in.rarpd service if it is not in use.
CVE-2002-0884 affects Solaris, Caldera UnixWare 7.1.1, Open UNIX 8.0, and specific versions of SunOS, including 5.7 and 5.8.
Exploitation of CVE-2002-0884 can involve sending crafted format strings to the syserr and error functions, leading to arbitrary code execution.
While CVE-2002-0884 is an older vulnerability, if outdated systems or software versions are still in use, they continue to pose a significant risk.