CVE-2018-14622

NameCVE-2018-14622
DescriptionA null-pointer dereference vulnerability was found in libtirpc before ...
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1487-1, ELA-33-1
Debian Bugs907608

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libtirpc (PTS)jessie, jessie (lts)0.2.5-1+deb8u3fixed
stretch0.2.5-1.2+deb9u1fixed
buster1.1.4-0.4fixed
sid, bullseye1.2.6-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libtirpcsource(unstable)0.2.5-1.3907608
libtirpcsourceexperimental1.0.2-0.1
libtirpcsourcejessie0.2.5-1+deb8u2DLA-1487-1
libtirpcsourcestretch0.2.5-1.2+deb9u1
libtirpcsourcewheezy0.2.2-5+deb7u2ELA-33-1

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=1620293
https://bugzilla.suse.com/show_bug.cgi?id=968175
http://git.linux-nfs.org/?p=steved/libtirpc.git;a=commit;h=1c77f7a869bdea2a34799d774460d1f9983d45f0

Search for package or bug name: Reporting problems