CVE-2002-1265: Medium severity gnu glibc vulnerability
Published Nov 12, 2002
·Updated
The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).
Affected Software
59 affected components
GNU glibc=2.2.2
SGI IRIX=6.5.16m
SGI IRIX=6.5.6
GNU glibc=2.1.2
GNU glibc=2.0.5
SGI IRIX=6.5.17f
GNU glibc=2.2.5
GNU glibc=2.0.6
SGI IRIX=6.5.1
SGI IRIX=6.5.14f
SGI IRIX=6.5.10
GNU glibc=2.1.1
GNU glibc=2.0.3
GNU glibc=2.3
GNU glibc=2.0
SGI IRIX=6.5.12
SGI IRIX=6.5.15f
GNU glibc=2.1.1.6
SGI IRIX=6.5.9
GNU glibc=2.1
SGI IRIX=6.5.16f
SGI IRIX=6.5.17m
GNU glibc=2.0.1
SGI IRIX=6.5.14m
SGI IRIX=6.5.3
GNU glibc=2.0.4
GNU glibc=2.0.2
GNU glibc=2.2.1
SGI IRIX=6.5.8
GNU glibc=2.1.3.10
SGI IRIX=6.5.5
SGI IRIX=6.5.4
SGI IRIX=2.3.1
SGI IRIX=6.5.15m
GNU glibc=2.2.3
SGI IRIX=6.5.11
SGI IRIX=6.5.2
SGI IRIX=6.5
SGI IRIX=6.5.7
GNU glibc=2.2.4
GNU glibc=2.1.3
SGI IRIX=6.5.13
GNU glibc=2.2
Apple iOS and macOS=10.0.2
Apple iOS and macOS=10.2.1
Apple iOS and macOS=10.1
Apple iOS and macOS=10.0.1
Apple iOS and macOS=10.0.3
Apple iOS and macOS=10.1.4
Apple iOS and macOS=10.0
Apple iOS and macOS=10.1.3
Apple iOS and macOS=10.1.5
Apple Mac OS X Server=10.2
Apple Mac OS X Server=10.2.1
Apple iOS and macOS=10.1.1
Apple Mac OS X Server=10.0
Apple iOS and macOS=10.2
Apple iOS and macOS=10.0.4
Apple iOS and macOS=10.1.2
Event History
Nov 12, 2002
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1265?
CVE-2002-1265 has a medium severity rating due to its potential for denial of service attacks.
2
How do I fix CVE-2002-1265?
To mitigate CVE-2002-1265, upgrade your libc implementations to versions that implement proper time-out mechanisms.
3
What systems are affected by CVE-2002-1265?
CVE-2002-1265 affects multiple versions of GNU C Library (glibc) and SGI IRIX.
4
What type of attack is possible with CVE-2002-1265?
CVE-2002-1265 could allow remote attackers to cause a denial of service by hanging the RPC functionality.
5
Is there a permanent resolution for CVE-2002-1265?
The permanent resolution for CVE-2002-1265 is to regularly apply updates and patches provided by software maintainers.