[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2016:0005 -- centos 7 rpcbind

ID: oval:org.secpod.oval:def:203812Date: (C)2016-01-20   (M)2022-10-10
Class: PATCHFamily: unix




The rpcbind utility is a server that converts RPC program numbers into universal addresses. It must be running on the host to be able to make RPC calls on a server on that machine. A use-after-free flaw related to the PMAP_CALLIT operation and TCP/UDP connections was discovered in rpcbind. A remote attacker could possibly exploit this flaw to crash the rpcbind service by performing a series of UDP and TCP calls. All rpcbind users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. If the rpcbind service is running, it will be automatically restarted after installing this update.

Platform:
CentOS 7
Product:
rpcbind
Reference:
CESA-2016:0005
CVE-2015-7236
CVE    1
CVE-2015-7236
CPE    2
cpe:/a:rpcbind:rpcbind
cpe:/o:centos:centos:7

© SecPod Technologies