CVE-2003-0028: Integer Overflow

Published Mar 19, 2003
ยท
Updated

Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.

Other sources

Integer overflow in the xdrmemgetbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.

Affected Software

165 affected components
GNU glibc=2.2.2
SGI IRIX=6.5.9f
SGI IRIX=6.5.16m
SGI IRIX=6.5.6
OpenAFS OpenAFS=1.1.1a
GNU glibc=2.1.2
SGI IRIX=6.5.4m
SGI IRIX=6.5.17f
SGI IRIX=6.5.3f
GNU glibc=2.1.1
GNU glibc=2.3
GNU glibc=2.3.1
OpenAFS OpenAFS=1.1
SGI IRIX=6.5.1
SGI IRIX=6.5.10
OpenAFS OpenAFS=1.0
SGI IRIX=6.5.10m
SGI IRIX=6.5.13m
SGI IRIX=6.5.4f
SGI IRIX=6.5.9m
OpenAFS OpenAFS=1.0.2
OpenAFS OpenAFS=1.2.1
SGI IRIX=6.5.14f
SGI IRIX=6.5.17
GNU glibc=2.2.5
OpenAFS OpenAFS=1.0.4
SGI IRIX=6.5.12
OpenAFS OpenAFS=1.2.4
SGI IRIX=6.5.12f
SGI IRIX=6.5.15f
SGI IRIX=6.5.15m
SGI IRIX=6.5.18f
GNU glibc=2.2.1
GNU glibc=2.3.2
OpenAFS OpenAFS=1.1.1
OpenAFS OpenAFS=1.2.5
SGI IRIX=6.5.13f
SGI IRIX=6.5.16f
SGI IRIX=6.5.19
SGI IRIX=6.5.4
SGI IRIX=6.5.3m
SGI IRIX=6.5.6f
SGI IRIX=6.5.8m
SGI IRIX=6.5.9
OpenAFS OpenAFS=1.0.1
OpenAFS OpenAFS=1.2.2
OpenAFS OpenAFS=1.3
OpenAFS OpenAFS=1.3.1
SGI IRIX=6.5.14
SGI IRIX=6.5.20
SGI IRIX=6.5.5
SGI IRIX=6.5.7f
SGI IRIX=6.5.7m
GNU glibc=2.1
OpenAFS OpenAFS=1.0.3
OpenAFS OpenAFS=1.2.2b
SGI IRIX=6.5.14m
SGI IRIX=6.5.15
SGI IRIX=6.5.17m
SGI IRIX=6.5.2f
SGI IRIX=6.5.2m
SGI IRIX=6.5.3
SGI IRIX=6.5.8
MIT Kerberos 5=1.2.5
MIT Kerberos 5=1.2.6
OpenAFS OpenAFS=1.0.4a
OpenAFS OpenAFS=1.2.3
SGI IRIX=6.5.12m
SGI IRIX=6.5.13
SGI IRIX=6.5.18
GNU glibc=2.1.3
GNU glibc=2.2
MIT Kerberos 5=1.2
MIT Kerberos 5=1.2.7
OpenAFS OpenAFS=1.2
OpenAFS OpenAFS=1.2.6
SGI IRIX=6.5.10f
SGI IRIX=6.5.16
SGI IRIX=6.5.18m
SGI IRIX=6.5.6m
SGI IRIX=6.5.7
GNU glibc=2.2.3
MIT Kerberos 5=1.2.1
MIT Kerberos 5=1.2.2
SGI IRIX=6.5.11
SGI IRIX=6.5.11f
SGI IRIX=6.5.2
GNU glibc=2.2.4
MIT Kerberos 5=1.2.3
MIT Kerberos 5=1.2.4
OpenAFS OpenAFS=1.2.2a
OpenAFS OpenAFS=1.3.2
SGI IRIX=6.5
SGI IRIX=6.5.11m
SGI IRIX=6.5.5f
SGI IRIX=6.5.5m
SGI IRIX=6.5.8f
HP Hp-ux Series 800=10.20
FreeBSD FreeBSD=4.1.1-stable
CRAY UNICOS=9.0
OpenBSD OpenBSD=2.8
FreeBSD FreeBSD=4.1.1-release
HP HP-UX=11.11
CRAY UNICOS=9.0.2.5
Sun Solaris=2.5.1
FreeBSD FreeBSD=4.4-stable
FreeBSD FreeBSD=4.5
FreeBSD FreeBSD=4.5-release
FreeBSD FreeBSD=4.7-stable
OpenBSD OpenBSD=3.1
OpenBSD OpenBSD=2.1
OpenBSD OpenBSD=2.9
Sun SunOS=5.7
CRAY UNICOS=6.0
CRAY UNICOS=6.0e
CRAY UNICOS=9.2.4
FreeBSD FreeBSD=4.2-stable
FreeBSD FreeBSD=4.5-stable
CRAY UNICOS=7.0
FreeBSD FreeBSD=4.3-release
FreeBSD FreeBSD=4.3-stable
FreeBSD FreeBSD=4.6-release
FreeBSD FreeBSD=4.6-stable
HP HP-UX=11.04
FreeBSD FreeBSD=4.2
FreeBSD FreeBSD=5.0
HP HP-UX=11.22
HP Hp-ux Series 700=10.20
OpenBSD OpenBSD=2.2
OpenBSD OpenBSD=2.3
OpenBSD OpenBSD=2.4
OpenBSD OpenBSD=3.2
Sun SunOS=5.8
CRAY UNICOS=8.0
CRAY UNICOS=8.3
FreeBSD FreeBSD=4.1.1
FreeBSD FreeBSD=4.4
FreeBSD FreeBSD=4.7
HP HP-UX=11.20
OpenBSD OpenBSD=2.0
OpenBSD OpenBSD=3.0
Sun Solaris=7.0
CRAY UNICOS=9.2
FreeBSD FreeBSD=4.3
FreeBSD FreeBSD=4.6
HP HP-UX=10.20
HP HP-UX=10.24
IBM AIX=4.3.3
OpenBSD OpenBSD=2.5
OpenBSD OpenBSD=2.6
Sun SunOS=5.5.1
Sun Solaris=9.0
Sun Solaris=9.0
CRAY UNICOS=6.1
FreeBSD FreeBSD=4.0
FreeBSD FreeBSD=4.1
HP HP-UX=11.00
IBM AIX=5.1
IBM AIX=5.2
OpenBSD OpenBSD=2.7
Sun Solaris=8.0
FreeBSD FreeBSD=4.7-release
FreeBSD FreeBSD=4.6.2
Sun Solaris=2.6
Sun SunOS

Event History

Mar 19, 2003
CVE Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionSeverity
Mar 21, 2003
CVE Published
via MITREยท10:00 AM
Data Sourced
via MITREยท10:00 AM
Description
Mar 25, 2003
Data Sourced
via NVDยท05:00 AM
RemedyDescriptionSeverityAffected Software
Aug 16, 2018
Data Sourced
02:18 AM
Affected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2003-0028?

CVE-2003-0028 is considered to have a high severity due to the potential for integer overflow vulnerabilities that can lead to denial of service or arbitrary code execution.

2

How do I fix CVE-2003-0028?

To fix CVE-2003-0028, you should upgrade your affected software to the latest version that addresses the integer overflow issue.

3

Which versions of software are affected by CVE-2003-0028?

CVE-2003-0028 affects various versions of the GNU C Library (glibc), MIT Kerberos 5, OpenAFS, SGI IRIX, and multiple versions of HP-UX and UNIX-like operating systems.

4

What types of vulnerabilities are associated with CVE-2003-0028?

CVE-2003-0028 is associated with integer overflow vulnerabilities that can be exploited to gain unauthorized access or crash the system.

5

Is CVE-2003-0028 still relevant today?

While CVE-2003-0028 is an older vulnerability, it remains relevant for systems still using the affected software versions or libraries that have not been patched.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
ยฉ 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203