|
|
|
Vulnerability Note VU#266817Multiple Sun RPC-based libc implementations fails to provide time-out mechanism when reading data from TCP connectionsOverviewA denial-of-service vulnerability exists in multiple vendor Sun RPC-based libc implementations.I. DescriptionMultiple vendor Sun RPC-based libc implementations fail to properly read data from TCP connections. As a result, a remote attacker can deny service to system daemons.II. ImpactA remote attacker can connect to a vulnerable service and cause the service to hang.III. SolutionApply a vendor patch when available.Systems Affected
References
This document was written by Ian A Finlay.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||