Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2017-8779
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data size during memory allocation for XDR strings, which allows remote attackers to cause a denial of service (memory consumption with no subsequent free) via a crafted UDP packet to port 111, aka rpcbomb.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
rpcbind 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
NTIRPC是一个使用在Linux系统中的用于nfs-ganesha的运输的独立RPC库。LIBTIRPC是一个使用在Linux系统中的包含支持使用远程过程调用(RPC)API程序的库的软件包。rpcbind是一个使用在Linux系统中的将RPC程序编号转换为通用地址的服务器。 rpcbind、LIBTIRPC和NTIRPC中存在资源管理错误漏洞,该漏洞源于程序在为XDR字符串分配内存时,没有确定最大RPC数据的大小。攻击者可通过向111端口发送特制的UDP数据包利用该漏洞造成拒绝服务(内存消耗)。以下产
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
-n/a n/a -
II. Public POCs for CVE-2017-8779
#POC DescriptionSource LinkShenlong Link
1CVE-2017-8779 aka RPCBombhttps://github.com/drbothen/GO-RPCBOMBPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2017-8779
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2017-8779

No comments yet


Leave a comment