Vulnerabilities > CVE-2002-1265 - Denial Of Service vulnerability in Multiple Vendor Sun RPC LibC TCP Time-Out

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
gnu
sgi
apple
nessus

Summary

The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).

Nessus

  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHNE_30090.NASL
    descriptions700_800 11.23 libnsl cumulative patch : A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS).
    last seen2020-06-01
    modified2020-06-02
    plugin id16725
    published2005-02-16
    reporterThis script is Copyright (C) 2005-2013 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/16725
    titleHP-UX PHNE_30090 : HP-UX Running RPC, Remote Denial of Service (DoS) (HPSBUX01020 SSRT2384 rev.2)
  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHKL_31500.NASL
    descriptions700_800 11.23 Sept04 base patch : The remote HP-UX host is affected by multiple vulnerabilities : - A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS). (HPSBUX01020 SSRT2384) - A potential vulnerability has been identified in HP-UX running the Veritas File System (VxFS) that may allow a local authorized user access to unauthorized data. - A potential security vulnerability has been identified with HP-UX running TCP/IP. The potential vulnerability could be exploited remotely to cause a Denial of Service (DoS). (HPSBUX02087 SSRT4728) - A potential security vulnerability has been found in HP-UX running rpc.ypupdated. The vulnerability could be exploited to allow remote unauthorized access. (HPSBUX01002 SSRT4688)
    last seen2020-06-01
    modified2020-06-02
    plugin id17400
    published2005-03-18
    reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/17400
    titleHP-UX PHKL_31500 : s700_800 11.23 Sept04 base patch
  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHNE_29211.NASL
    descriptions700_800 11.11 ONC/NFS General Release/Performance Patch : The remote HP-UX host is affected by multiple vulnerabilities : - The error messages returned by rpc.mountd can be used to determine whether a file exists. (HPSBUX00272 SSRT3596) - A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS). (HPSBUX01020 SSRT2384)
    last seen2020-06-01
    modified2020-06-02
    plugin id16928
    published2005-02-16
    reporterThis script is Copyright (C) 2005-2013 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/16928
    titleHP-UX PHNE_29211 : s700_800 11.11 ONC/NFS General Release/Performance Patch
  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHNE_29210.NASL
    descriptions700_800 11.00 ONC/NFS General Release/Performance Patch : The remote HP-UX host is affected by multiple vulnerabilities : - A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS). (HPSBUX01020 SSRT2384) - The error messages returned by rpc.mountd can be used to determine whether a file exists. (HPSBUX00272 SSRT3596)
    last seen2020-06-01
    modified2020-06-02
    plugin id16929
    published2005-02-16
    reporterThis script is Copyright (C) 2005-2013 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/16929
    titleHP-UX PHNE_29210 : s700_800 11.00 ONC/NFS General Release/Performance Patch
  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHNE_30091.NASL
    descriptions700_800 11.23 NIS/NIS+ cumulative patch : A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS).
    last seen2020-06-01
    modified2020-06-02
    plugin id56836
    published2012-03-06
    reporterThis script is Copyright (C) 2012-2013 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/56836
    titleHP-UX PHNE_30091 : HP-UX Running RPC, Remote Denial of Service (DoS) (HPSBUX01020 SSRT2384 rev.2)
  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHNE_30094.NASL
    descriptions700_800 11.23 NFS cumulative patch : A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS).
    last seen2020-06-01
    modified2020-06-02
    plugin id56839
    published2012-03-06
    reporterThis script is Copyright (C) 2012-2013 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/56839
    titleHP-UX PHNE_30094 : HP-UX Running RPC, Remote Denial of Service (DoS) (HPSBUX01020 SSRT2384 rev.2)
  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHNE_30092.NASL
    descriptions700_800 11.23 RPC commands and daemons cumulative patch : A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS).
    last seen2020-06-01
    modified2020-06-02
    plugin id56837
    published2012-03-06
    reporterThis script is Copyright (C) 2012-2013 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/56837
    titleHP-UX PHNE_30092 : HP-UX Running RPC, Remote Denial of Service (DoS) (HPSBUX01020 SSRT2384 rev.2)
  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHNE_29449.NASL
    descriptions700_800 11.22 ONC/NFS General Release/Performance Patch : The remote HP-UX host is affected by multiple vulnerabilities : - A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS). (HPSBUX01020 SSRT2384) - Potential buffer overflow in XDR library. (HPSBUX00215 SSRT2336) - Potential buffer overflow in xdrmem_getbytes() and related functions. (HPSBUX00252 SSRT2439) - The error messages returned by rpc.mountd can be used to determine whether a file exists. (HPSBUX00272 SSRT3596)
    last seen2020-06-01
    modified2020-06-02
    plugin id16911
    published2005-02-16
    reporterThis script is Copyright (C) 2005-2013 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/16911
    titleHP-UX PHNE_29449 : s700_800 11.22 ONC/NFS General Release/Performance Patch
  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHNE_30808.NASL
    descriptions700_800 11.04 (VVOS) ONC/NFS General Release/Perf Patch : A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS).
    last seen2020-06-01
    modified2020-06-02
    plugin id16607
    published2005-02-16
    reporterThis script is Copyright (C) 2005-2013 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/16607
    titleHP-UX PHNE_30808 : HP-UX Running RPC, Remote Denial of Service (DoS) (HPSBUX01020 SSRT2384 rev.2)
  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHNE_30093.NASL
    descriptions700_800 11.23 Lock Manager cumulative patch : A potential security vulnerability has been identified with HP-UX running RPC services, where the vulnerability may be exploited by an unauthorized remote user to create a denial of service (DoS).
    last seen2020-06-01
    modified2020-06-02
    plugin id56838
    published2012-03-06
    reporterThis script is Copyright (C) 2012-2013 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/56838
    titleHP-UX PHNE_30093 : HP-UX Running RPC, Remote Denial of Service (DoS) (HPSBUX01020 SSRT2384 rev.2)

Oval

accepted2005-06-01T03:30:00.000-04:00
classvulnerability
contributors
nameBrian Soby
organizationThe MITRE Corporation
descriptionThe Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).
familyunix
idoval:org.mitre.oval:def:2248
statusaccepted
submitted2005-04-13T12:00:00.000-04:00
titleSun RPC No Timeout Denial of Service on TCP Ports
version35