ZeroHour

CVE-2018-14622

CVSS 3.1
7.5 high
EPSS
4%p90
Published
()
Modified
Description

A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new connections.

Vendors
libtirpc projectcanonicaldebianredhat
Products
libtirpc, ubuntu linux, debian linux, enterprise linux, enterprise linux desktop, enterprise linux server aus, enterprise linux server eus, enterprise linux workstation
Weakness
CWE-252
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.