Vulnerabilities > CVE-2002-1265
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).
Vulnerable Configurations
Nessus
NASL family HP-UX Local Security Checks NASL id HPUX_PHNE_30090.NASL description s700_800 11.23 libnsl cumulative patch : A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS). last seen 2020-06-01 modified 2020-06-02 plugin id 16725 published 2005-02-16 reporter This script is Copyright (C) 2005-2013 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/16725 title HP-UX PHNE_30090 : HP-UX Running RPC, Remote Denial of Service (DoS) (HPSBUX01020 SSRT2384 rev.2) NASL family HP-UX Local Security Checks NASL id HPUX_PHKL_31500.NASL description s700_800 11.23 Sept04 base patch : The remote HP-UX host is affected by multiple vulnerabilities : - A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS). (HPSBUX01020 SSRT2384) - A potential vulnerability has been identified in HP-UX running the Veritas File System (VxFS) that may allow a local authorized user access to unauthorized data. - A potential security vulnerability has been identified with HP-UX running TCP/IP. The potential vulnerability could be exploited remotely to cause a Denial of Service (DoS). (HPSBUX02087 SSRT4728) - A potential security vulnerability has been found in HP-UX running rpc.ypupdated. The vulnerability could be exploited to allow remote unauthorized access. (HPSBUX01002 SSRT4688) last seen 2020-06-01 modified 2020-06-02 plugin id 17400 published 2005-03-18 reporter This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/17400 title HP-UX PHKL_31500 : s700_800 11.23 Sept04 base patch NASL family HP-UX Local Security Checks NASL id HPUX_PHNE_29211.NASL description s700_800 11.11 ONC/NFS General Release/Performance Patch : The remote HP-UX host is affected by multiple vulnerabilities : - The error messages returned by rpc.mountd can be used to determine whether a file exists. (HPSBUX00272 SSRT3596) - A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS). (HPSBUX01020 SSRT2384) last seen 2020-06-01 modified 2020-06-02 plugin id 16928 published 2005-02-16 reporter This script is Copyright (C) 2005-2013 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/16928 title HP-UX PHNE_29211 : s700_800 11.11 ONC/NFS General Release/Performance Patch NASL family HP-UX Local Security Checks NASL id HPUX_PHNE_29210.NASL description s700_800 11.00 ONC/NFS General Release/Performance Patch : The remote HP-UX host is affected by multiple vulnerabilities : - A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS). (HPSBUX01020 SSRT2384) - The error messages returned by rpc.mountd can be used to determine whether a file exists. (HPSBUX00272 SSRT3596) last seen 2020-06-01 modified 2020-06-02 plugin id 16929 published 2005-02-16 reporter This script is Copyright (C) 2005-2013 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/16929 title HP-UX PHNE_29210 : s700_800 11.00 ONC/NFS General Release/Performance Patch NASL family HP-UX Local Security Checks NASL id HPUX_PHNE_30091.NASL description s700_800 11.23 NIS/NIS+ cumulative patch : A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS). last seen 2020-06-01 modified 2020-06-02 plugin id 56836 published 2012-03-06 reporter This script is Copyright (C) 2012-2013 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/56836 title HP-UX PHNE_30091 : HP-UX Running RPC, Remote Denial of Service (DoS) (HPSBUX01020 SSRT2384 rev.2) NASL family HP-UX Local Security Checks NASL id HPUX_PHNE_30094.NASL description s700_800 11.23 NFS cumulative patch : A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS). last seen 2020-06-01 modified 2020-06-02 plugin id 56839 published 2012-03-06 reporter This script is Copyright (C) 2012-2013 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/56839 title HP-UX PHNE_30094 : HP-UX Running RPC, Remote Denial of Service (DoS) (HPSBUX01020 SSRT2384 rev.2) NASL family HP-UX Local Security Checks NASL id HPUX_PHNE_30092.NASL description s700_800 11.23 RPC commands and daemons cumulative patch : A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS). last seen 2020-06-01 modified 2020-06-02 plugin id 56837 published 2012-03-06 reporter This script is Copyright (C) 2012-2013 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/56837 title HP-UX PHNE_30092 : HP-UX Running RPC, Remote Denial of Service (DoS) (HPSBUX01020 SSRT2384 rev.2) NASL family HP-UX Local Security Checks NASL id HPUX_PHNE_29449.NASL description s700_800 11.22 ONC/NFS General Release/Performance Patch : The remote HP-UX host is affected by multiple vulnerabilities : - A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS). (HPSBUX01020 SSRT2384) - Potential buffer overflow in XDR library. (HPSBUX00215 SSRT2336) - Potential buffer overflow in xdrmem_getbytes() and related functions. (HPSBUX00252 SSRT2439) - The error messages returned by rpc.mountd can be used to determine whether a file exists. (HPSBUX00272 SSRT3596) last seen 2020-06-01 modified 2020-06-02 plugin id 16911 published 2005-02-16 reporter This script is Copyright (C) 2005-2013 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/16911 title HP-UX PHNE_29449 : s700_800 11.22 ONC/NFS General Release/Performance Patch NASL family HP-UX Local Security Checks NASL id HPUX_PHNE_30808.NASL description s700_800 11.04 (VVOS) ONC/NFS General Release/Perf Patch : A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS). last seen 2020-06-01 modified 2020-06-02 plugin id 16607 published 2005-02-16 reporter This script is Copyright (C) 2005-2013 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/16607 title HP-UX PHNE_30808 : HP-UX Running RPC, Remote Denial of Service (DoS) (HPSBUX01020 SSRT2384 rev.2) NASL family HP-UX Local Security Checks NASL id HPUX_PHNE_30093.NASL description s700_800 11.23 Lock Manager cumulative patch : A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS). last seen 2020-06-01 modified 2020-06-02 plugin id 56838 published 2012-03-06 reporter This script is Copyright (C) 2012-2013 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/56838 title HP-UX PHNE_30093 : HP-UX Running RPC, Remote Denial of Service (DoS) (HPSBUX01020 SSRT2384 rev.2)
Oval
accepted | 2005-06-01T03:30:00.000-04:00 | ||||
class | vulnerability | ||||
contributors |
| ||||
description | The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang). | ||||
family | unix | ||||
id | oval:org.mitre.oval:def:2248 | ||||
status | accepted | ||||
submitted | 2005-04-13T12:00:00.000-04:00 | ||||
title | Sun RPC No Timeout Denial of Service on TCP Ports | ||||
version | 35 |
References
- http://www.kb.cert.org/vuls/id/266817
- http://www.securityfocus.com/bid/6103
- http://www.iss.net/security_center/static/10539.php
- http://www.info.apple.com/usen/security/security_updates.html
- http://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-2004.0800.1
- ftp://patches.sgi.com/support/free/security/advisories/20021103-01-P
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/51082
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2248