UBUNTU-CVE-2017-8779
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-8779
UBUNTU-CVE-2017-8779
Summary:
Details: rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data size during memory allocation for XDR strings, which allows remote attackers to cause a denial of service (memory consumption with no subsequent free) via a crafted UDP packet to port 111, aka rpcbomb.
References: https://ubuntu.com/security/CVE-2017-8779, http://www.openwall.com/lists/oss-security/2017/05/04/1, https://github.com/guidovranken/rpcbomb/, http://openwall.com/lists/oss-security/2017/05/03/12, http://openwall.com/lists/oss-security/2017/05/04/1, https://guidovranken.wordpress.com/2017/05/03/rpcbomb-remote-rpcbind-denial-of-service-patches/, https://ubuntu.com/security/notices/USN-3759-1, https://ubuntu.com/security/notices/USN-3759-2, https://ubuntu.com/security/notices/USN-4986-1, https://ubuntu.com/security/notices/USN-4986-2, https://www.cve.org/CVERecord?id=CVE-2017-8779
Affected packages
Package
Name: libtirpc
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
