CVE-2018-14622
7.5HIGHA null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server
Publicado: 8/30/2018Atualizado: 11/21/2024
Descrição
A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new connections.
Análise IADesenvolvido por IA
Produtos Afetados
libtirpc_projectlibtirpc
canonicalubuntu_linux
14.04
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
debiandebian_linux
8.0
redhatenterprise_linux
7.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_server_aus
7.4
redhatenterprise_linux_server_eus
7.4
redhatenterprise_linux_server_eus
7.5
redhatenterprise_linux_server_eus
7.6
redhatenterprise_linux_workstation
7.0
Referências
- http://git.linux-nfs.org/?p=steved/libtirpc.git%3Ba=commit%3Bh=1c77f7a869bdea2a34799d774460d1f9983d45f0
- https://access.redhat.com/errata/RHBA-2017:1991Third Party Advisory
- https://bugzilla.novell.com/show_bug.cgi?id=968175Issue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14622Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00034.htmlMailing ListThird Party Advisory
- https://usn.ubuntu.com/3759-1/Third Party Advisory
- https://usn.ubuntu.com/3759-2/Third Party Advisory
- http://git.linux-nfs.org/?p=steved/libtirpc.git%3Ba=commit%3Bh=1c77f7a869bdea2a34799d774460d1f9983d45f0
- https://access.redhat.com/errata/RHBA-2017:1991Third Party Advisory
- https://bugzilla.novell.com/show_bug.cgi?id=968175Issue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14622Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00034.htmlMailing ListThird Party Advisory
- https://usn.ubuntu.com/3759-1/Third Party Advisory
- https://usn.ubuntu.com/3759-2/Third Party Advisory