Name | CVE-2018-14622 |
Description | A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new connections. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-1487-1, ELA-33-1 |
Debian Bugs | 907608 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
libtirpc (PTS) | jessie, jessie (lts) | 0.2.5-1+deb8u3 | fixed |
stretch | 0.2.5-1.2+deb9u1 | fixed | |
buster (security), buster, buster (lts) | 1.1.4-0.4+deb10u1 | fixed | |
bullseye (security), bullseye | 1.3.1-1+deb11u1 | fixed | |
bookworm | 1.3.3+ds-1 | fixed | |
sid, trixie | 1.3.4+ds-1.3 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
libtirpc | source | experimental | 1.0.2-0.1 | |||
libtirpc | source | wheezy | 0.2.2-5+deb7u2 | ELA-33-1 | ||
libtirpc | source | jessie | 0.2.5-1+deb8u2 | DLA-1487-1 | ||
libtirpc | source | stretch | 0.2.5-1.2+deb9u1 | |||
libtirpc | source | (unstable) | 0.2.5-1.3 | 907608 |
https://bugzilla.redhat.com/show_bug.cgi?id=1620293
https://bugzilla.suse.com/show_bug.cgi?id=968175
http://git.linux-nfs.org/?p=steved/libtirpc.git;a=commit;h=1c77f7a869bdea2a34799d774460d1f9983d45f0