debian · CVE-2003-0028

Quick triage

Priority: not yet assigned Published: Updated: Thu, 18 Jun 2026 01:58:16 GMT

View at Official debian advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2003-0028 not yet assigned priority: Debian including 3 source packages (dietlibc, glibc, krb5), 15 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 15.

Description:

Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.

cvelogic Threat Intelligence