CVE-2002-2003: Medium severity Compaq Tru64 vulnerability
Published Dec 31, 2002
·Updated
ypbind in Compaq Tru64 4.0F, 4.0G, 5.0A, 5.1 and 5.1A allows remote attackers to cause the process to core dump via certain network packets generated by nmap.
Affected Software
5 affected components
Compaq Tru64=4.0g
Compaq Tru64=5.0a
Compaq Tru64=4.0f
Compaq Tru64=5.1a
Compaq Tru64=5.1
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Jul 14, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2003?
CVE-2002-2003 is considered to have a high severity due to its potential to cause a denial of service through process crashes.
2
How do I fix CVE-2002-2003?
To fix CVE-2002-2003, users should apply the relevant patches provided by Compaq for their Tru64 versions.
3
Which versions of Compaq Tru64 are affected by CVE-2002-2003?
CVE-2002-2003 affects Compaq Tru64 versions 4.0F, 4.0G, 5.0A, 5.1, and 5.1A.
4
What kind of attack does CVE-2002-2003 describe?
CVE-2002-2003 describes a denial of service attack that can be caused by specific network packets sent to ypbind.
5
Is there a workaround for CVE-2002-2003 while waiting for a patch?
While waiting for a patch for CVE-2002-2003, it is advisable to restrict access to ypbind and limit network exposure.