MNBSD-2015-12: rpcbind remote denial of service

Severity: Unknown

Affected Package: rpcbind

Summary: rpcbind remote denial of service

Description

In rpcbind(8), netbuf structures were copied directly, resulting in two netbuf structures referencing one shared address buffer. When one structure was freed, access to the other produced an undefined result that could crash the rpcbind daemon, allowing a remote attacker to cause a denial of service. The patch was later revised on October 2 to fix issues with NIS.

Affected Versions

rpcbind

Recommendations

No specific recommendations provided.

References

Additional Information

Aliases: CVE-2015-7236

Published: September 30, 2015
Last Modified: September 30, 2015