Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2017-8779
Description:rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data size during memory allocation for XDR strings, which allows remote attackers to cause a denial of service (memory consumption with no subsequent free) via a crafted UDP packet to port 111, aka rpcbomb.
Test IDs: 1.3.6.1.4.1.25623.1.0.882722   1.3.6.1.4.1.25623.1.1.10.2017.0183   1.3.6.1.4.1.25623.1.0.882721   1.3.6.1.4.1.25623.1.0.890937   1.3.6.1.4.1.25623.1.1.4.2017.1306.1   1.3.6.1.4.1.25623.1.0.882718   1.3.6.1.4.1.25623.1.1.12.2021.4986.2   1.3.6.1.4.1.25623.1.1.2.2017.1097   1.3.6.1.4.1.25623.1.0.871820   1.3.6.1.4.1.25623.1.1.10.2017.0184   1.3.6.1.4.1.25623.1.1.4.2017.1328.1   1.3.6.1.4.1.25623.1.1.13.2017.191.02   1.3.6.1.4.1.25623.1.0.844972   1.3.6.1.4.1.25623.1.0.703845   1.3.6.1.4.1.25623.1.1.4.2017.1468.1   1.3.6.1.4.1.25623.1.0.871816   1.3.6.1.4.1.25623.1.1.13.2017.191.01   1.3.6.1.4.1.25623.1.0.851556   1.3.6.1.4.1.25623.1.1.4.2017.1314.1   1.3.6.1.4.1.25623.1.1.2.2017.1096   1.3.6.1.4.1.25623.1.0.851558   1.3.6.1.4.1.25623.1.1.2.2020.2015   1.3.6.1.4.1.25623.1.1.2.2020.1614   1.3.6.1.4.1.25623.1.0.890936   1.3.6.1.4.1.25623.1.0.871819   1.3.6.1.4.1.25623.1.0.150662   1.3.6.1.4.1.25623.1.1.4.2017.1336.1   1.3.6.1.4.1.25623.1.0.872677   1.3.6.1.4.1.25623.1.0.882717   1.3.6.1.4.1.25623.1.0.871815   1.3.6.1.4.1.25623.1.1.2.2020.1761   1.3.6.1.4.1.25623.1.0.872689   1.3.6.1.4.1.25623.1.1.2.2020.1567   1.3.6.1.4.1.25623.1.1.2.2017.1102   1.3.6.1.4.1.25623.1.1.2.2017.1103  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2017-8779
BugTraq ID: 98325
http://www.securityfocus.com/bid/98325
Debian Security Information: DSA-3845 (Google Search)
http://www.debian.org/security/2017/dsa-3845
https://www.exploit-db.com/exploits/41974/
https://security.gentoo.org/glsa/201706-07
http://openwall.com/lists/oss-security/2017/05/03/12
http://openwall.com/lists/oss-security/2017/05/04/1
https://github.com/drbothen/GO-RPCBOMB
https://github.com/guidovranken/rpcbomb/
https://guidovranken.wordpress.com/2017/05/03/rpcbomb-remote-rpcbind-denial-of-service-patches/
RedHat Security Advisories: RHBA-2017:1497
https://access.redhat.com/errata/RHBA-2017:1497
RedHat Security Advisories: RHSA-2017:1262
https://access.redhat.com/errata/RHSA-2017:1262
RedHat Security Advisories: RHSA-2017:1263
https://access.redhat.com/errata/RHSA-2017:1263
RedHat Security Advisories: RHSA-2017:1267
https://access.redhat.com/errata/RHSA-2017:1267
RedHat Security Advisories: RHSA-2017:1268
https://access.redhat.com/errata/RHSA-2017:1268
RedHat Security Advisories: RHSA-2017:1395
https://access.redhat.com/errata/RHSA-2017:1395
http://www.securitytracker.com/id/1038532
https://usn.ubuntu.com/3759-1/
https://usn.ubuntu.com/3759-2/




© 1998-2025 E-Soft Inc. All rights reserved.