The svc_dg_getargs function in libtirpc 0.2.3 and earlier allows remote attackers to cause a denial of service (rpcbind crash) via a Sun RPC request with crafted arguments that trigger a free of an invalid pointer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libtirpc | Libtirpc_project | * | 0.2.3 (including) |
Libtirpc | Libtirpc_project | 0.1.8 (including) | 0.1.8 (including) |
Libtirpc | Libtirpc_project | 0.1.9 (including) | 0.1.9 (including) |
Libtirpc | Libtirpc_project | 0.1.10 (including) | 0.1.10 (including) |
Libtirpc | Libtirpc_project | 0.1.11 (including) | 0.1.11 (including) |
Libtirpc | Libtirpc_project | 0.2.0 (including) | 0.2.0 (including) |
Libtirpc | Libtirpc_project | 0.2.1 (including) | 0.2.1 (including) |
Libtirpc | Libtirpc_project | 0.2.2 (including) | 0.2.2 (including) |
Red Hat Enterprise Linux 6 | RedHat | libtirpc-0:0.2.1-6.el6_4 | * |
Ntirpc | Ubuntu | eoan | * |
Ntirpc | Ubuntu | trusty | * |
Ntirpc | Ubuntu | xenial | * |