RPCBind / Portmap Malformed RPC Request Denial of Service Vulnerability
BID:3400
Info
RPCBind / Portmap Malformed RPC Request Denial of Service Vulnerability
| Bugtraq ID: | 3400 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-1124 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was announced in an HP Security Advisory on October 1, 2001. |
| Vulnerable: |
SGI IRIX 6.5.15 m SGI IRIX 6.5.15 f SGI IRIX 6.5.14 m SGI IRIX 6.5.14 f SGI IRIX 6.5.13 m SGI IRIX 6.5.13 f SGI IRIX 6.5.12 m SGI IRIX 6.5.12 f SGI IRIX 6.5.11 m SGI IRIX 6.5.11 f SGI IRIX 6.5.10 SGI IRIX 6.5.9 SGI IRIX 6.5.8 SGI IRIX 6.5.7 SGI IRIX 6.5.6 SGI IRIX 6.5.5 SGI IRIX 6.5.4 SGI IRIX 6.5.3 SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 HP HP-UX 11.11 HP HP-UX 11.0 4 HP HP-UX 11.0 |
| Not Vulnerable: | |
Discussion
RPCBind / Portmap Malformed RPC Request Denial of Service Vulnerability
A problem in some rpcbind/portmap implementations could make it possible for remote users to deny service to legitimate users of rpc dependent services. Malformed RPC requests may cause the portmapper to crash. This may be due to a buffer overflow condition.
This makes it possible for a remote user to exploit the service, and potentially deny rpc dependent service access such as NIS to other users of the system.
One of the conditions has been described by HP as 'random buffer overflows' and is present when the system is under heavy load. It is not known if code execution is possible. Additionally, similar conditions have been reported in rpcbind/portmap implementations for SGI IRIX.
A problem in some rpcbind/portmap implementations could make it possible for remote users to deny service to legitimate users of rpc dependent services. Malformed RPC requests may cause the portmapper to crash. This may be due to a buffer overflow condition.
This makes it possible for a remote user to exploit the service, and potentially deny rpc dependent service access such as NIS to other users of the system.
One of the conditions has been described by HP as 'random buffer overflows' and is present when the system is under heavy load. It is not known if code execution is possible. Additionally, similar conditions have been reported in rpcbind/portmap implementations for SGI IRIX.
Exploit / POC
RPCBind / Portmap Malformed RPC Request Denial of Service Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
RPCBind / Portmap Malformed RPC Request Denial of Service Vulnerability
Solution:
Fixes available:
HP HP-UX 11.0
HP HP-UX 11.0 4
HP HP-UX 11.11
SGI IRIX 6.5.11 f
SGI IRIX 6.5.11 m
SGI IRIX 6.5.12 f
SGI IRIX 6.5.12 m
SGI IRIX 6.5.13 f
SGI IRIX 6.5.13 m
SGI IRIX 6.5.14 f
SGI IRIX 6.5.14 m
SGI IRIX 6.5.15 m
SGI IRIX 6.5.15 f
Solution:
Fixes available:
HP HP-UX 11.0
-
HP PHNE_24034
http://itrc.hp.com -
HP PHNE_28102
http://itrc.hp.com/
HP HP-UX 11.0 4
-
HP PHNE_25077
http://itrc.hp.com
HP HP-UX 11.11
-
HP PHNE_24035
http://itrc.hp.com
SGI IRIX 6.5.11 f
SGI IRIX 6.5.11 m
SGI IRIX 6.5.12 f
SGI IRIX 6.5.12 m
SGI IRIX 6.5.13 f
SGI IRIX 6.5.13 m
SGI IRIX 6.5.14 f
SGI IRIX 6.5.14 m
SGI IRIX 6.5.15 m
SGI IRIX 6.5.15 f
References
RPCBind / Portmap Malformed RPC Request Denial of Service Vulnerability
References:
References: