The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2.25 mishandle failures of buffer deserialization, which allows remote attackers to cause a denial of service (virtual memory allocation, or memory consumption if an overcommit setting is not used) via a crafted UDP packet to port 111, a related issue to CVE-2017-8779. NOTE: [Information provided from upstream and references
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T16:48:22.588Z
Reserved: 2017-05-07T00:00:00
Link: CVE-2017-8804
No data.
Status : Deferred
Published: 2017-05-07T18:29:00.157
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-8804
OpenCVE Enrichment
No data.