← Vulnerability feed

Vulnerability record · CVE-2003-0028 · published 25 March 2003

CVE-2003-0028: Gnu glibc vulnerability

Gnu · Glibc

Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.

7.5 CVSS 2.0 High EPSS 15% · top 3.4%
7.5CVSS 2.0 base score
15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
13Affected product versions listed by NVD
50References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-008.txt.asc
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0140.html
http://marc.info/?l=bugtraq&m=104810574423662&w=2
http://marc.info/?l=bugtraq&m=104811415301340&w=2
http://marc.info/?l=bugtraq&m=104860855114117&w=2
http://marc.info/?l=bugtraq&m=104878237121402&w=2
http://marc.info/?l=bugtraq&m=105362148313082&w=2
http://www.cert.org/advisories/CA-2003-10.html PatchThird Party AdvisoryUS Government Resource
http://www.debian.org/security/2003/dsa-266
http://www.debian.org/security/2003/dsa-272
http://www.debian.org/security/2003/dsa-282
http://www.eeye.com/html/Research/Advisories/AD20030318.html ExploitVendor Advisory
http://www.kb.cert.org/vuls/id/516825 US Government Resource
http://www.linuxsecurity.com/advisories/engarde_advisory-3024.html
http://www.mandriva.com/security/advisories?name=MDKSA-2003:037
http://www.novell.com/linux/security/advisories/2003_027_glibc.html
http://www.redhat.com/support/errata/RHSA-2003-051.html
http://www.redhat.com/support/errata/RHSA-2003-052.html
http://www.redhat.com/support/errata/RHSA-2003-089.html
http://www.redhat.com/support/errata/RHSA-2003-091.html
http://www.securityfocus.com/archive/1/315638/30/25430/threaded
http://www.securityfocus.com/archive/1/316931/30/25250/threaded
http://www.securityfocus.com/archive/1/316960/30/25250/threaded
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A230
https://security.netapp.com/advisory/ntap-20150122-0002/
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-008.txt.asc
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0140.html
http://marc.info/?l=bugtraq&m=104810574423662&w=2
http://marc.info/?l=bugtraq&m=104811415301340&w=2
http://marc.info/?l=bugtraq&m=104860855114117&w=2
http://marc.info/?l=bugtraq&m=104878237121402&w=2
http://marc.info/?l=bugtraq&m=105362148313082&w=2
http://www.cert.org/advisories/CA-2003-10.html PatchThird Party AdvisoryUS Government Resource
http://www.debian.org/security/2003/dsa-266
http://www.debian.org/security/2003/dsa-272
http://www.debian.org/security/2003/dsa-282
http://www.eeye.com/html/Research/Advisories/AD20030318.html ExploitVendor Advisory
http://www.kb.cert.org/vuls/id/516825 US Government Resource
http://www.linuxsecurity.com/advisories/engarde_advisory-3024.html
http://www.mandriva.com/security/advisories?name=MDKSA-2003:037

Track CVE-2003-0028 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-1823PHP-CGI query string option injection enables remote code executionPHP versions before 5.3.12 and 5.4.x before 5.4.2, when run as a CGI script (php-cgi), mishandle query strings that lack an equals sign, allowing com…KEVEPSS 100%analysed7.8CVE-2023-4911GNU C Library ld.so GLIBC_TUNABLES heap buffer overflowThe GNU C Library dynamic loader ld.so mishandles the GLIBC_TUNABLES environment variable, causing a heap-based buffer overflow and out-of-bounds wri…KEVEPSS 81%analysed10.0CVE-2024-43102Freebsd use after free vulnerabilityConcurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM can lead to decreasing the r…EPSS 0.68%10.0CVE-2018-17160Freebsd out-of-bounds write vulnerabilityIn FreeBSD before 11.2-STABLE(r341486) and 11.2-RELEASE-p6, insufficient bounds checking in one of the device models provided by bhyve can permit a g…EPSS 3.3%10.0CVE-2015-0235glibc gethostbyname heap buffer overflow (GHOST)CVE-2015-0235 is a heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2 and other 2.x versions before 2.18. It is reach…EPSS 95%analysed10.0CVE-2014-3954Freebsd memory buffer overflow vulnerabilityStack-based buffer overflow in rtsold in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (crash) or possibly execut…EPSS 3.9%10.0CVE-2012-0131Hp distributed computing environment vulnerabilityDistributed Computing Environment (DCE) 1.8 and 1.9 on HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service or possibly …EPSS 7.4%10.0CVE-2011-4862telnetd encryption key buffer overflow allows remote code executionA buffer overflow in libtelnet/encrypt.c in telnetd affects FreeBSD 7.3 through 9.0, MIT krb5-appl 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU …EPSS 95%analysed

Source: NIST National Vulnerability Database (record CVE-2003-0028), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.