Vulnerability Name: | CVE-2002-0884 (CCN-9150) | ||||||||
Assigned: | 2002-05-22 | ||||||||
Published: | 2002-05-22 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | Multiple format string vulnerabilities in in.rarpd (ARP server) on Solaris, Caldera UnixWare and Open UNIX, and possibly other operating systems, allows remote attackers to execute arbitrary code via format strings that are not properly handled in the functions (1) syserr and (2) error. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CALDERA Type: UNKNOWN CSSA-2002-SCO.29 Source: CCN Type: Caldera International, Inc. Security Advisory CSSA-2002-SCO.29 UnixWare 7.1.1 Open UNIX 8.0.0 : in.rarpd format string vulnerability in error() and syserr() Source: CCN Type: BugTraq Mailing List, Tue May 21 2002 - 21:06:43 CDT [DER Adv #7] - Multiple Vulnerabilities in solaris in.rarpd Source: VULNWATCH Type: UNKNOWN 20020521 [VulnWatch] [DER Adv #7] - Multiple Vulnerabilities in solaris in.rarpd Source: MITRE Type: CNA CVE-2002-0884 Source: MITRE Type: CNA CVE-2002-0885 Source: BUGTRAQ Type: UNKNOWN 20020522 [DER Adv #7] - Multiple Vulnerabilities in solaris in.rarpd Source: XF Type: Vendor Advisory solaris-inrarpd-code-execution(9150) Source: CCN Type: OSVDB ID: 8707 Multiple Vendor in.rarpd Format String Arbitrary Code Execution Source: CCN Type: OSVDB ID: 8708 Multiple Vendor in.rarpd Buffer Overflow Arbitrary Code Execution Source: BID Type: Patch, Vendor Advisory 4791 Source: CCN Type: BID-4791 Multiple Vendor In.Rarpd Multiple Vulnerabilities Source: XF Type: UNKNOWN solaris-inrarpd-code-execution(9150) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||
BACK |