Description
The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).
Affected products
- Apple / mac_os_x10.0 – 10.0
- Apple / mac_os_x10.0.3 – 10.0.3
- Apple / mac_os_x10.0.2 – 10.0.2
- Apple / mac_os_x10.0.1 – 10.0.1
- Apple / mac_os_x10.2.1 – 10.2.1
- Apple / mac_os_x10.2 – 10.2
- Apple / mac_os_x10.1.5 – 10.1.5
- Apple / mac_os_x10.1.4 – 10.1.4
- Apple / mac_os_x10.1.3 – 10.1.3
- Apple / mac_os_x10.1.2 – 10.1.2
- Apple / mac_os_x10.1.1 – 10.1.1
- Apple / mac_os_x10.1 – 10.1
- Apple / mac_os_x10.0.4 – 10.0.4
- Apple / mac_os_x_server10.2 – 10.2
- Apple / mac_os_x_server10.0 – 10.0
- Apple / mac_os_x_server10.2.1 – 10.2.1
- gnu / glibc2.2.3 – 2.2.3
- gnu / glibc2.2.4 – 2.2.4
- gnu / glibc2.2.5 – 2.2.5
- gnu / glibc2.3 – 2.3
- gnu / glibc2.2.1 – 2.2.1
- gnu / glibc2.0.1 – 2.0.1
- gnu / glibc2.0.2 – 2.0.2
- gnu / glibc2.0.3 – 2.0.3
- gnu / glibc2.0.4 – 2.0.4
- gnu / glibc2.0.5 – 2.0.5
- gnu / glibc2.0.6 – 2.0.6
- gnu / glibc2.1 – 2.1
- gnu / glibc2.1.1 – 2.1.1
- gnu / glibc2.1.1.6 – 2.1.1.6
- gnu / glibc2.1.2 – 2.1.2
- gnu / glibc2.1.3 – 2.1.3
- gnu / glibc2.1.3.10 – 2.1.3.10
- gnu / glibc2.2 – 2.2
- gnu / glibc2.0 – 2.0
- gnu / glibc2.2.2 – 2.2.2
- sgi / irix6.5.14m – 6.5.14m
- sgi / irix6.5.15f – 6.5.15f
- sgi / irix6.5.15m – 6.5.15m
- sgi / irix6.5.16f – 6.5.16f
- sgi / irix6.5.16m – 6.5.16m
- sgi / irix6.5.17f – 6.5.17f
- sgi / irix6.5.17m – 6.5.17m
- sgi / irix6.5.14f – 6.5.14f
- sgi / irix6.5.13 – 6.5.13
- sgi / irix6.5.12 – 6.5.12
- sgi / irix6.5.11 – 6.5.11
- sgi / irix6.5.10 – 6.5.10
- sgi / irix6.5.9 – 6.5.9
- sgi / irix6.5.8 – 6.5.8
- sgi / irix6.5.7 – 6.5.7
- sgi / irix6.5.6 – 6.5.6
- sgi / irix6.5.5 – 6.5.5
- sgi / irix6.5.4 – 6.5.4
- sgi / irix6.5.3 – 6.5.3
- sgi / irix6.5.2 – 6.5.2
- sgi / irix6.5.1 – 6.5.1
- sgi / irix6.5 – 6.5
- sgi / irix2.3.1 – 2.3.1
References
- VENDOR_ADVISORYhttp://www.info.apple.com/usen/security/security_updates.html
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2248
- MISChttp://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-2004.0800.1
- MISChttp://www.iss.net/security_center/static/10539.php
- MISChttp://www.securityfocus.com/bid/6103
- MISChttp://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/51082
- VENDOR_ADVISORYftp://patches.sgi.com/support/free/security/advisories/20021103-01-P
- MISChttp://www.kb.cert.org/vuls/id/266817