PT-2015-3373 · None+3 · Libtirpc+3

Laura Pardo

·

Published

2015-07-13

·

Updated

2023-02-03

·

CVE-2018-14622

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libtirpc versions prior to 0.3.3-rc3
Description A null-pointer dereference issue was found in the makefd xprt() function, where the return value was not checked in all instances. This could lead to a crash when the server exhausts the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new connections.
Recommendations For versions prior to 0.3.3-rc3, update to version 0.3.3-rc3 or later to resolve the issue. As a temporary workaround, consider restricting the number of new connections to prevent the server from exhausting its available file descriptors.

Fix

Unchecked Return Value

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1401
BDU:2019-00430
CVE-2018-14622
DLA-1487-1
SUSE-SU-2018:3146-1
USN-3759-1
USN-3759-2

Affected Products

Alt Linux
Suse
Ubuntu
Libtirpc