CVE-2017-8804
published 2017-05-07CVE-2017-8804: The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2.25 mishandle failures of buffer deserialization, which allows remote…
PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
7.67%
94.0th percentile
The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2.25 mishandle failures of buffer deserialization, which allows remote attackers to cause a denial of service (virtual memory allocation, or memory consumption if an overcommit setting is not used) via a crafted UDP packet to port 111, a related issue to CVE-2017-8779. NOTE: [Information provided from upstream and references
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | glibc | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
glibc: memory leak in sunrpc when decoding malformed XDR
vendor_redhat·2017-05-08·CVSS 7.5
CVE-2017-8804 [HIGH] CWE-400 glibc: memory leak in sunrpc when decoding malformed XDR
glibc: memory leak in sunrpc when decoding malformed XDR
The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2.25 mishandle failures of buffer deserialization, which allows remote attackers to cause a denial of service (virtual memory allocation, or memory consumption if an overcommit setting is not used) via a crafted UDP packet to port 111, a related issue to CVE-2017-8779. NOTE: [Information provided from upstream and references
Package: compat-glibc (Red Hat Enterprise Linux 5) - Will not fix
Package: glibc (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-glibc (Red Hat Enterprise Linux 6) - Will not fix
Package: glibc (Red Hat Enterprise Linux 6) - Will not fix
Package: compat-glibc (Red Hat Enterprise Linux 7) - Will not fix
Package: gli
GHSA
GHSA-pgff-5mf5-cw73: ** DISPUTED ** The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2017-8804 [HIGH] CWE-502 GHSA-pgff-5mf5-cw73: ** DISPUTED ** The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2
** DISPUTED ** The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2.25 mishandle failures of buffer deserialization, which allows remote attackers to cause a denial of service (virtual memory allocation, or memory consumption if an overcommit setting is not used) via a crafted UDP packet to port 111, a related issue to CVE-2017-8779. NOTE: [Information provided from upstream and references]
No detection rules found.
No public exploits indexed.
HackerOne
rpcbind "rpcbomb" CVE-2017-8779, CVE-2017-8804
hackerone·2019-10-14·CVSS 7.5
CVE-2017-8779 [HIGH] rpcbind "rpcbomb" CVE-2017-8779, CVE-2017-8804
rpcbind "rpcbomb" CVE-2017-8779, CVE-2017-8804
Description: this allowed an attacker to easily disrupt a remote system through excessive memory consumption.
Writeup: https://guidovranken.wordpress.com/2017/05/03/rpcbomb-remote-rpcbind-denial-of-service-patches/
Demonstration video: https://www.youtube.com/watch?v=b38H3oEgrQw (this video shows that the attack doesn't necessarily just crashes the rpcbind process, but that the entire system can slow down severely because it has to resort to swap memory, even if overcommit is enabled. This implies scope=changed in the CVSS. But I filled out unchanged to be consistent with the official assessment)
CVSS score: https://nvd.nist.gov/vuln/detail/CVE-2017-8779
rpcbind/libtirpc: CVE-2017-8779 http://git.linux-nfs.org/?p=steved/libtirpc.git;a=commi
Bugzilla
CVE-2017-8804 glibc: memory leak in sunrpc when decoding malformed XDR [fedora-all]
bugzilla·2017-05-08·CVSS 7.5
CVE-2017-8804 [HIGH] CVE-2017-8804 glibc: memory leak in sunrpc when decoding malformed XDR [fedora-all]
CVE-2017-8804 glibc: memory leak in sunrpc when decoding malformed XDR [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2017-8804 glibc: memory leak in sunrpc when decoding malformed XDR
bugzilla·2017-05-08·CVSS 7.5
CVE-2017-8804 [HIGH] CVE-2017-8804 glibc: memory leak in sunrpc when decoding malformed XDR
CVE-2017-8804 glibc: memory leak in sunrpc when decoding malformed XDR
A crafted XDR message containing a string or bytes entity with a particularly large size but no content could cause xdr_opaque to leak virtual memory. Since the memory is never accessed, physical pages are not mapped (unless sysctl vm.overcommit_memory=2 is in effect). This was discovered in the wake of CVE-2017-8779.
Upstream issue:
https://sourceware.org/bugzilla/show_bug.cgi?id=21461
Upstream patch:
https://sourceware.org/ml/libc-alpha/2017-05/msg00105.html
CVE assignment:
https://seclists.org/oss-sec/2017/q2/218
Discussion:
Created glibc tracking bugs for this issue:
Affects: fedora-all [bug 1448796]
---
Per discussion on the libc-alpha mailing list (linked https://sourceware.org/bugzilla/show_bug.cgi?id
http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-02/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-02/msg00049.htmlhttp://www.openwall.com/lists/oss-security/2017/05/05/2http://www.securityfocus.com/bid/98339https://bugzilla.suse.com/show_bug.cgi?id=1037559#c7https://seclists.org/oss-sec/2017/q2/228https://sourceware.org/bugzilla/show_bug.cgi?id=21461https://sourceware.org/legacy-ml/libc-alpha/2017-05/msg00128.htmlhttps://sourceware.org/legacy-ml/libc-alpha/2017-05/msg00129.htmlhttps://sourceware.org/ml/libc-alpha/2017-05/msg00105.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-02/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-02/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-02/msg00049.htmlhttp://www.openwall.com/lists/oss-security/2017/05/05/2http://www.securityfocus.com/bid/98339https://bugzilla.suse.com/show_bug.cgi?id=1037559#c7https://seclists.org/oss-sec/2017/q2/228https://sourceware.org/bugzilla/show_bug.cgi?id=21461https://sourceware.org/legacy-ml/libc-alpha/2017-05/msg00128.htmlhttps://sourceware.org/legacy-ml/libc-alpha/2017-05/msg00129.htmlhttps://sourceware.org/ml/libc-alpha/2017-05/msg00105.html
2017-05-07
Published