CVE-2018-14621
Last modified
CVE-2018-14621 is a vulnerability of currently unknown severity. An infinite loop vulnerability was found in libtirpc before version 1.0.2-rc2. With the port to using poll rather than select, exhaustion of file descriptors would cause the server to enter an infinite loop, consuming a large amount of CPU time and denying service to other clients until restarted.. EPSS estimates a 2.26% chance of exploitation in the next 30 days.
Description
An infinite loop vulnerability was found in libtirpc before version 1.0.2-rc2. With the port to using poll rather than select, exhaustion of file descriptors would cause the server to enter an infinite loop, consuming a large amount of CPU time and denying service to other clients until restarted.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Libtirpc Project | Libtirpc | <= 1.0.1 | — |
| Libtirpc Project | Libtirpc | 1.0.2 | Rc1 |
References
- https://bugzilla.novell.com/show_bug.cgi?id=968175Issue Tracking, Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14621Issue Tracking, Patch, Third Party Advisory
- https://bugzilla.novell.com/show_bug.cgi?id=968175Issue Tracking, Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14621Issue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-14621?
How severe is CVE-2018-14621?
How do I fix CVE-2018-14621?
Are you affected by CVE-2018-14621?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
