CVE-2017-8779: High severity Rpcbind Project Rpcbind vulnerability

Published May 4, 2017
·
Updated

Last updated 18 August 2025

Other sources

Rpcbind does not consider the maximum RPC data size during memory allocation for XDR strings, which allows remote attackers to cause a denial of service (memory consumption with no subsequent free) via a crafted UDP packet to port 111, aka rpcbomb.

References:

http://seclists.org/oss-sec/2017/q2/209 https://guidovranken.wordpress.com/2017/05/03/rpcbomb-remote-rpcbind-denial-of-service-patches/

Red Hat

rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data size during memory allocation for XDR strings, which allows remote attackers to cause a denial of service (memory consumption with no subsequent free) via a crafted UDP packet to port 111, aka rpcbomb.

Launchpad

Affected Software

6 affected componentsFixes available
Rpcbind Project Rpcbind<=0.2.4
Libtirpc Project Libtirpc<=1.0.1
Ntirpc Project Ntirpc<=1.4.3
debian/libtirpc
1.3.1-1+deb11u11.3.3+ds-11.3.6+ds-1
debian/ntirpc
3.4-24.3-26.3-26.3-4
debian/rpcbind
1.2.5-91.2.6-61.2.7-1

Event History

May 4, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·03:03 PM
DescriptionSeverityAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:41 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·05:27 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·05:28 PM
DescriptionAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2017-8779?

CVE-2017-8779 has a high severity rating due to its potential to cause denial of service through excessive memory consumption.

2

How do I fix CVE-2017-8779?

To fix CVE-2017-8779, upgrade to the recommended versions of rpcbind, libtirpc, or ntirpc as specified in the vulnerability report.

3

What systems are affected by CVE-2017-8779?

CVE-2017-8779 affects versions of rpcbind up to 0.2.4, libtirpc up to 1.0.1, and ntirpc up to 1.4.3.

4

Can CVE-2017-8779 be exploited remotely?

Yes, CVE-2017-8779 can be exploited remotely via crafted UDP packets sent to port 111.

5

What is the potential impact of CVE-2017-8779 on servers?

The potential impact of CVE-2017-8779 on servers includes denial of service, leading to unavailability and potential downtime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203