Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2018:3146-1

Опубликовано: 15 окт. 2018
Источник: suse-cvrf

Описание

Security update for libtirpc

This update for libtirpc fixes the following issues:

Security issues fixed:

  • CVE-2018-14621: libtirpc: Infinite loop in EMFILE case in svc_vc.c (bsc#1106519)
  • CVE-2018-14622: libtirpc: Segmentation fault in makefd_xprt return value in svc_vc.c (bsc#1106517)

Список пакетов

SUSE Linux Enterprise Server 11 SP4
libtirpc1-0.2.1-1.13.6.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4
libtirpc1-0.2.1-1.13.6.1
SUSE Linux Enterprise Software Development Kit 11 SP4
libtirpc-devel-0.2.1-1.13.6.1

Описание

An infinite loop vulnerability was found in libtirpc before version 1.0.2-rc2. With the port to using poll rather than select, exhaustion of file descriptors would cause the server to enter an infinite loop, consuming a large amount of CPU time and denying service to other clients until restarted.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libtirpc1-0.2.1-1.13.6.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4:libtirpc1-0.2.1-1.13.6.1
SUSE Linux Enterprise Software Development Kit 11 SP4:libtirpc-devel-0.2.1-1.13.6.1

Ссылки

Описание

A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new connections.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libtirpc1-0.2.1-1.13.6.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4:libtirpc1-0.2.1-1.13.6.1
SUSE Linux Enterprise Software Development Kit 11 SP4:libtirpc-devel-0.2.1-1.13.6.1

Ссылки