PT-2017-4166 · Microsoft+6 · Ntirpc+7

Guido Vranken

·

Published

2017-05-03

·

Updated

2024-08-05

·

CVE-2017-8779

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions rpcbind versions 0.2.4 and earlier LIBTIRPC versions 1.0.1 and 1.0.2-rc through 1.0.2-rc3 NTIRPC versions 1.4.3 and earlier
Description The issue allows remote attackers to cause a denial of service due to memory consumption with no subsequent free, via a crafted UDP packet to port 111. This is related to the server's handling of RPC ports and unlimited resource allocation, which can be exploited by a remote attacker to cause a service disruption.
Recommendations For rpcbind versions 0.2.4 and earlier, consider restricting access to port 111 to minimize the risk of exploitation. For LIBTIRPC versions 1.0.1 and 1.0.2-rc through 1.0.2-rc3, restrict access to the vulnerable RPC service until a patch is available. For NTIRPC versions 1.4.3 and earlier, as a temporary workaround, consider disabling the RPC service to prevent remote attackers from exploiting the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1816
ALT-PU-2018-2163
BDU:2021-05819
CESA-2017_1262
CESA-2017_1263
CESA-2017_1267
CESA-2017_1268
CVE-2017-8779
DLA-936-1
DLA-937-1
DSA-3845-1
MGASA-2017-0183
OPENSUSE-SU-2017_1381-1
OPENSUSE-SU-2017_1412-1
OPENSUSE-SU-2024:11304-1
RHSA-2017:1262
RHSA-2017:1263
RHSA-2017:1267
RHSA-2017:1268
RHSA-2017:1395
RHSA-2017_1262
RHSA-2017_1263
RHSA-2017_1267
RHSA-2017_1268
SUSE-SU-2017:1306-1
SUSE-SU-2017:1314-1
SUSE-SU-2017:1328-1
SUSE-SU-2017:1336-1
SUSE-SU-2017:1468-1
SUSE-SU-2017_1306-1
SUSE-SU-2017_1314-1
SUSE-SU-2017_1328-1
SUSE-SU-2017_1336-1
SUSE-SU-2017_1468-1
USN-3759-1
USN-3759-2
USN-4986-1
USN-4986-2
USN-4986-3
USN-4986-4

Affected Products

Alt Linux
Centos
Libtirpc
Ntirpc
Red Hat
Suse
Ubuntu
Rpcbind