The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2.25 mishandle failures of buffer deserialization, which allows remote attackers to cause a denial of service (virtual memory allocation, or memory consumption if an overcommit setting is not used) via a crafted UDP packet to port 111, a related issue to CVE-2017-8779. NOTE: [Information provided from upstream and references
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Glibc | Gnu | 2.25 (including) | 2.25 (including) |
Eglibc | Ubuntu | precise | * |
Glibc | Ubuntu | artful | * |
Glibc | Ubuntu | vivid/stable-phone-overlay | * |
Glibc | Ubuntu | vivid/ubuntu-core | * |
Glibc | Ubuntu | yakkety | * |
Glibc | Ubuntu | zesty | * |