CVE-2017-8804

Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 07 May 2017, 18:00
Last modified:05 Aug 2024, 16:48

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
7.8 HIGH
v2.0 (nvd)
EPSS Score
6.05% LOW
6% probability +2.29%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

07 May 2017, 18:00
Published
Vulnerability first disclosed
05 Aug 2024, 16:48
Last Modified
Vulnerability information updated

Description

The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2.25 mishandle failures of buffer deserialization, which allows remote attackers to cause a denial of service (virtual memory allocation, or memory consumption if an overcommit setting is not used) via a crafted UDP packet to port 111, a related issue to CVE-2017-8779. NOTE: [Information provided from upstream and references

CVSS Metrics

  • v3.0HIGHScore: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0HIGHScore: 7.8AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS Trends

Current EPSS score: 6.05% Percentile: 91%

Techniques & Countermeasures

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Systems

  • gnuglibc

    2.25

References (11)