CVE-2021-46828
20.07.2022, 06:15
In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libtirpc_project | libtirpc | 𝑥 < 1.3.3 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libtirpc |
| ||||||||||||||||||||
| ntirpc |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libtirpc-devel |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| libtirpc-netconfig |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| libtirpc3 |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| libtirpc3-32bit |
|
Red Hat Enterprise Linux Releases
Common Weakness Enumeration
References