libtirpc-1.3.3-0.el9

エラータID: AXSA:2022-4495:04

Release date: 
Thursday, December 22, 2022 - 06:49
Subject: 
libtirpc-1.3.3-0.el9
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

The libtirpc packages contain SunLib's implementation of transport-independent remote procedure call (TI-RPC) documentation, which includes a library required by programs in the nfs-utils and rpcbind packages.

Security Fix(es):

* libtirpc: DoS vulnerability with lots of connections (CVE-2021-46828)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2021-46828
In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. libtirpc-1.3.3-0.el9.src.rpm
    MD5: 8a6fc95851a3e06a62a4f09a257faf0e
    SHA-256: 61d1a84ac319da464dd6748727d2a798947501291e7346d7a34ffed66626c96e
    Size: 563.21 kB

Asianux Server 9 for x86_64
  1. libtirpc-1.3.3-0.el9.x86_64.rpm
    MD5: b4559f27defe637412c66b5bb8a13f6f
    SHA-256: c4ab0e505ecc62d6844f35f3057a51afa0a3dd0eb3cebbf97a28ec26327fd485
    Size: 92.37 kB
  2. libtirpc-devel-1.3.3-0.el9.x86_64.rpm
    MD5: 3fd3363e957c104efc4c9eaf114b550b
    SHA-256: 9f5117ce1b6ba91e100b3fd13321d56a7a6c42143259fff7388ddc73d037c9aa
    Size: 112.27 kB
  3. libtirpc-1.3.3-0.el9.i686.rpm
    MD5: cfecd0fb33fcbec7bc31480d42d64ebd
    SHA-256: 66fcc90769b5a6d1d63662b072ffc59f0741dbcd00ee1022440e6fd26e3bbf19
    Size: 100.35 kB
  4. libtirpc-devel-1.3.3-0.el9.i686.rpm
    MD5: c44001850b6c3af9c9391dac36292ff3
    SHA-256: be924f6c43382563d84456399c057b8930423ccb1966b0b9c5bb2528d1173a09
    Size: 112.31 kB