Описание
Security update for libtirpc
This update for libtirpc fixes the following issues:
Security issues fixed:
- CVE-2018-14621: libtirpc: Infinite loop in EMFILE case in svc_vc.c (bsc#1106519)
- CVE-2018-14622: libtirpc: Segmentation fault in makefd_xprt return value in svc_vc.c (bsc#1106517)
Список пакетов
SUSE Linux Enterprise Server 11 SP4
SUSE Linux Enterprise Server for SAP Applications 11 SP4
SUSE Linux Enterprise Software Development Kit 11 SP4
Ссылки
- Link for SUSE-SU-2018:3146-1
- E-Mail link for SUSE-SU-2018:3146-1
- SUSE Security Ratings
- SUSE Bug 1106517
- SUSE Bug 1106519
- SUSE Bug 968175
- SUSE CVE CVE-2018-14621 page
- SUSE CVE CVE-2018-14622 page
Описание
An infinite loop vulnerability was found in libtirpc before version 1.0.2-rc2. With the port to using poll rather than select, exhaustion of file descriptors would cause the server to enter an infinite loop, consuming a large amount of CPU time and denying service to other clients until restarted.
Затронутые продукты
Ссылки
- CVE-2018-14621
- SUSE Bug 1106519
Описание
A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new connections.
Затронутые продукты
Ссылки
- CVE-2018-14622
- SUSE Bug 1106517
- SUSE Bug 968175