Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-14622

Опубликовано: 03 мар. 2016
Источник: redhat
CVSS3: 5.3

Описание

A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new connections.

A null-pointer dereference vulnerability was found in libtirpc. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new connections.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2libntirpcNot affected
Red Hat Ceph Storage 3libntirpcNot affected
Red Hat Enterprise Linux 6libtirpcWill not fix
Red Hat Enterprise Linux 8libtirpcNot affected
Red Hat OpenShift Enterprise 3libtirpcNot affected
Red Hat Storage 3libntirpcNot affected
Red Hat Virtualization 4libtirpcNot affected
Red Hat Enterprise Linux 7libtirpcFixedRHBA-2017:199101.08.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-252
https://bugzilla.redhat.com/show_bug.cgi?id=1620293libtirpc: Segmentation fault in makefd_xprt return value in svc_vc.c

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new connections.

CVSS3: 7.5
nvd
больше 7 лет назад

A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new connections.

CVSS3: 7.5
debian
больше 7 лет назад

A null-pointer dereference vulnerability was found in libtirpc before ...

CVSS3: 7.5
github
больше 3 лет назад

A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new connections.

CVSS3: 7.5
fstec
больше 10 лет назад

Уязвимость функции makefd_xprt() библиотеки предоставления протокола RPC libtirpc, позволяющая нарушителю вызвать отказ в обслуживании

5.3 Medium

CVSS3