7.5

CVE-2018-14622

A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new connections.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Libtirpc Project ≫ Libtirpc Version < 0.3.3
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Debian ≫ Debian Linux Version 8.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Desktop Version 7.0 HwPlatform x64
Redhat ≫ Enterprise Linux Workstation Version 7.0 HwPlatform x64
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.86% 0.888
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat 5.3 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-252 Unchecked Return Value

The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.

https://usn.ubuntu.com/3759-1/
Third Party Advisory
https://usn.ubuntu.com/3759-2/
Third Party Advisory
https://bugzilla.novell.com/show_bug.cgi?id=968175
Third Party Advisory
Issue Tracking
http://git.linux-nfs.org/?p=steved/libtirpc.git%3Ba=commit%3Bh=1c77f7a869bdea2a34799d774460d1f9983d45f0
https://access.redhat.com/errata/RHBA-2017:1991
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14622
Third Party Advisory
Issue Tracking
https://lists.debian.org/debian-lts-announce/2018/08/msg00034.html
Third Party Advisory
Mailing List