[0.4.8][LIBTIRPC] Fix CVE-2018-14622 CORE-15005, and CVE-2018-14621 CORE-15407
authorJoachim Henze <Joachim.Henze@reactos.org>
Sat, 26 Mar 2022 11:53:22 +0000 (12:53 +0100)
committerJoachim Henze <Joachim.Henze@reactos.org>
Sat, 26 Mar 2022 11:53:22 +0000 (12:53 +0100)
commit755f146887e8762c578d517a0948b84f13e5c02d
tree9cbd1c6a4546bec033c61cbb0298dc046007d532
parentabdff006f8f8086f2cd391895df1a7a8110251de
[0.4.8][LIBTIRPC] Fix CVE-2018-14622 CORE-15005, and CVE-2018-14621 CORE-15407

The chance for us to get attacked is rather low, because
LIBTIRPC is used solely for the nfs service and
I pushed aggressively years ago to have that turned from
'Automatic' to 'Manual' already.
I doubt many used this service, that does not exist on real Windows at all.
Attacks may result in Denial-Of-Service.

For details check:
https://nvd.nist.gov/vuln/detail/CVE-2018-14622
https://nvd.nist.gov/vuln/detail/CVE-2018-14621

Fixes picked from:
0.4.11-dev-93-g 000bbe074ed29d1efe39d4d65c81d1c1ead07c93 CVE-2018-14622 CORE-15005
0.4.11-dev-887-g f5f3ff86eafd51bd34665fdfed892a7fc3785879 CVE-2018-14621 CORE-15407
dll/3rdparty/libtirpc/src/svc_vc.c