CVE-2002-0884
Multiple format string vulnerabilities in in.rarpd (ARP server) on Solaris, Caldera UnixWare and Open UNIX, and possibly other operating systems, allows remote attackers to execute arbitrary code via format strings that are not properly handled in the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.76%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple format string vulnerabilities in in.rarpd (ARP server) on Solaris, Caldera UnixWare and Open UNIX, and possibly other operating systems, allows remote attackers to execute arbitrary code via format strings that are not properly handled in the functions (1) syserr and (2) error.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.76% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- caldera/unixware · caldera/openunix · sun/sunos
- Source
- cve@mitre.org
References
- ftp://ftp.caldera.com/pub/updates/OpenUNIX/CSSA-2002-SCO.29/CSSA-2002-SCO.29.txt
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0074.html
- http://online.securityfocus.com/archive/1/273584
- http://www.iss.net/security_center/static/9150.phpVendor Advisory
- http://www.securityfocus.com/bid/4791Patch, Vendor Advisory
- ftp://ftp.caldera.com/pub/updates/OpenUNIX/CSSA-2002-SCO.29/CSSA-2002-SCO.29.txt
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0074.html
- http://online.securityfocus.com/archive/1/273584
- http://www.iss.net/security_center/static/9150.phpVendor Advisory
- http://www.securityfocus.com/bid/4791Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.