PT-2013-1185 · None+3 · Libtirpc-Devel+5

Michael Armstrong

·

Publicado

2013-05-30

·

Atualizado

2022-09-20

·

CVE-2013-1950

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions libtirpc versions 0.2.1 through 0.2.3 libtirpc-devel versions 0.2.1 libtirpc-debuginfo versions 0.2.1
Description The issue allows remote attackers to cause a denial of service, potentially leading to disruption of protected information. This can be exploited remotely. The svc dg getargs function in libtirpc is vulnerable to a denial of service attack via a Sun RPC request with crafted arguments that trigger a free of an invalid pointer.
Recommendations For libtirpc versions 0.2.1 through 0.2.3, consider updating to a version later than 0.2.3 to resolve the issue. For libtirpc-devel versions 0.2.1, update to a version later than 0.2.1. For libtirpc-debuginfo versions 0.2.1, update to a version later than 0.2.1. As a temporary workaround, consider restricting access to the svc dg getargs function until a patch is available.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1332
BDU:2015-07034
BDU:2015-07035
BDU:2015-07036
BDU:2015-09007
BDU:2015-09008
BDU:2015-09009
CESA-2013_0884
CVE-2013-1950
RHSA-2013:0884
RHSA-2013_0884

Produtos afetados

Alt Linux
Centos
Red Hat
Libtirpc
Libtirpc-Debuginfo
Libtirpc-Devel