CVE-2003-0689
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/10/2003
Last modified:
16/06/2026
Description
The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number of groups, which can cause a buffer overflow.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:redhat:enterprise_linux:2.1:*:advanced_server:*:*:*:*:* | ||
| cpe:2.3:o:redhat:enterprise_linux:2.1:*:advanced_server_ia64:*:*:*:*:* | ||
| cpe:2.3:o:redhat:enterprise_linux:2.1:*:enterprise_server:*:*:*:*:* | ||
| cpe:2.3:o:redhat:enterprise_linux:2.1:*:enterprise_server_ia64:*:*:*:*:* | ||
| cpe:2.3:o:redhat:enterprise_linux:2.1:*:workstation:*:*:*:*:* | ||
| cpe:2.3:o:redhat:enterprise_linux:2.1:*:workstation_ia64:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



