A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new connections.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade libtirpc | Apr 24, 2020 | Aug 30, 2018 |
| Debian | — | Upgrade libtirpc | Feb 19, 2019 | Aug 30, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libtirpc | Sep 16, 2021 | Aug 30, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libtirpc | Jan 20, 2021 | Aug 30, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 30, 2018 |
| Suse | — | Upgrade libtirpc-develUpgrade libtirpc1 | Oct 17, 2018 | Aug 30, 2018 |
| Ubuntu | — | Upgrade libtirpc1Upgrade libtirpc-dev | Sep 18, 2018 | Aug 30, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub