← Vulnerability feed

Vulnerability record · CVE-2002-0391 · published 12 August 2002

CVE-2002-0391: SunRPC xdr_array integer overflow enables remote code execution

Freebsd · Freebsd

The xdr_array function in SunRPC-derived RPC libraries (libc, glibc, dietlibc and others) contains an integer overflow when processing the argument count. A remote attacker can pass a large number of arguments through RPC services such as rpc.cmsd and dmispd, corrupting memory. Because the flaw sits in widely shared RPC code, it affects many operating systems and services at once.

9.8 CVSS 3.1 Critical EPSS 58% · top 0.9% CWE-190 · Integer overflow
9.8CVSS 3.1 base score, v2 10.0
58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
76References, 8 tagged exploit
16 Jun 2026Last modified by NVD

Description

Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, remote code execution in shared RPC code, and very high EPSS despite absence from KEV.

What it is

The xdr_array function in SunRPC-derived RPC libraries (libc, glibc, dietlibc and others) contains an integer overflow when processing the argument count. A remote attacker can pass a large number of arguments through RPC services such as rpc.cmsd and dmispd, corrupting memory. Because the flaw sits in widely shared RPC code, it affects many operating systems and services at once.

Impact

Successful exploitation allows a remote attacker to execute arbitrary code, typically with the privileges of the RPC service, which on many systems is root. This gives full control of the affected host.

Attack surface

Reachable over the network through RPC services that call xdr_array, including rpc.cmsd and dmispd. The CVSS vector shows no privileges and no user interaction required, so any host exposing a vulnerable RPC service is directly reachable.

Exploitation

Not listed in CISA KEV, but EPSS is 0.58133 (99th percentile), indicating high predicted exploitation activity. Multiple references are tagged Exploit, confirming public exploit material exists.

What to do

  • Apply vendor patches for the RPC libraries and affected services (Sun, Microsoft, FreeBSD, OpenBSD and Linux distributions) as the first action.
  • Disable or block RPC services that are not required, particularly rpc.cmsd and dmispd.
  • Restrict RPC ports with host and network firewalls so only trusted hosts can reach them.
  • Where patching is not possible, isolate affected systems from untrusted networks.
  • Monitor vendor advisories for updated fixes since many original reference links are broken.

Detection

  • Monitor RPC traffic for unusually large argument counts or malformed XDR payloads targeting rpc.cmsd, dmispd and similar services.
  • Watch for unexpected process crashes or restarts of RPC daemons, which can indicate exploitation attempts.
  • Alert on new or unusual outbound connections or child processes spawned by RPC service accounts.
  • Audit exposed RPC ports and flag any internet-facing RPC services in the environment.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-055.0.txt Broken Link
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-011.txt.asc Broken Link
ftp://patches.sgi.com/support/free/security/advisories/20020801-01-A Broken Link
ftp://patches.sgi.com/support/free/security/advisories/20020801-01-P Broken Link
http://archives.neohapsis.com/archives/aix/2002-q4/0002.html Broken Link
http://archives.neohapsis.com/archives/bugtraq/2002-07/0514.html Broken Link
http://archives.neohapsis.com/archives/hp/2002-q3/0077.html Broken Link
http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20823 Broken LinkVendor Advisory
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000515 Broken Link
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000535 Broken Link
http://marc.info/?l=bugtraq&m=102813809232532&w=2 ExploitMailing List
http://marc.info/?l=bugtraq&m=102821785316087&w=2 ExploitMailing List
http://marc.info/?l=bugtraq&m=102821928418261&w=2 ExploitMailing List
http://marc.info/?l=bugtraq&m=102831443208382&w=2 ExploitMailing List
http://marc.info/?l=bugtraq&m=103158632831416&w=2 Mailing List
http://online.securityfocus.com/advisories/4402 Broken LinkThird Party AdvisoryVDB Entry
http://online.securityfocus.com/archive/1/285740 Broken LinkThird Party AdvisoryVDB Entry
http://rhn.redhat.com/errata/RHSA-2002-166.html Broken Link
http://rhn.redhat.com/errata/RHSA-2002-172.html Broken Link
http://www.cert.org/advisories/CA-2002-25.html PatchThird Party AdvisoryUS Government Resource
http://www.debian.org/security/2002/dsa-142 Broken Link
http://www.debian.org/security/2002/dsa-143 Broken Link
http://www.debian.org/security/2002/dsa-146 Broken Link
http://www.debian.org/security/2002/dsa-149 Broken Link
http://www.debian.org/security/2003/dsa-333 Broken Link
http://www.iss.net/security_center/static/9170.php Broken Link
http://www.kb.cert.org/vuls/id/192995 Third Party AdvisoryUS Government Resource
http://www.linuxsecurity.com/advisories/other_advisory-2399.html Broken Link
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:057 Broken Link
http://www.redhat.com/support/errata/RHSA-2002-167.html Broken Link
http://www.redhat.com/support/errata/RHSA-2002-173.html Broken Link
http://www.redhat.com/support/errata/RHSA-2003-168.html Broken Link
http://www.redhat.com/support/errata/RHSA-2003-212.html Broken Link
http://www.securityfocus.com/bid/5356 Broken LinkThird Party AdvisoryVDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-057 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A42 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4728 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9 Broken Link
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-055.0.txt Broken Link
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-011.txt.asc Broken Link

Track CVE-2002-0391 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2013-3918Microsoft Windows InformationCardSigninHelper ActiveX out-of-bounds writeThe InformationCardSigninHelper ActiveX control in icardie.dll contains an out-of-bounds write that can be triggered by a crafted web page rendered i…KEVEPSS 74%analysed8.8CVE-2011-3402Microsoft Windows TrueType Font Parsing Remote Code ExecutionThe TrueType font parsing engine in win32k.sys on multiple Windows versions fails to properly handle crafted font data, allowing remote code executio…KEVEPSS 78%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed8.8CVE-2009-1537Microsoft DirectShow QuickTime Parser NULL Byte Overwrite RCEThe QuickTime Movie Parser Filter in quartz.dll (DirectShow, DirectX 7.0 through 9.0c) contains an unspecified NULL byte overwrite flaw. A crafted Qu…KEVEPSS 51%analysed7.8CVE-2013-5065Microsoft Windows NDProxy.sys kernel local privilege escalationNDProxy.sys in the Windows kernel on Windows XP SP2/SP3 and Server 2003 SP2 fails to properly validate input, letting a local user escalate privilege…KEVEPSS 35%analysed7.8CVE-2013-3660Microsoft Windows win32k EPATHOBJ pointer flaw allows privilege escalationThe EPATHOBJ::pprFlattenRec function in win32k.sys fails to properly initialize a pointer for the next object in a list, letting a local user gain wr…KEVEPSS 39%analysed7.8CVE-2012-0151Microsoft Windows Authenticode Signature Verification PE Digest Validation FlawThe Authenticode Signature Verification function (WinVerifyTrust) in multiple Microsoft Windows versions fails to properly validate the digest of a s…KEVEPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2002-0391), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.