CVE-2010-2064: High severity Rpcbind Project Rpcbind vulnerability
Published May 27, 2010
·Updated
rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr.
Affected Software
2 affected componentsFixes available
Rpcbind Project Rpcbind=0.2.0
debian/rpcbind
1.2.5-91.2.6-61.2.7-1
Event History
May 27, 2010
CVE Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionSeverity
Oct 29, 2019
CVE Published
via MITRE·09:01 PM
Data Sourced
via MITRE·09:01 PM
DescriptionWeakness
Feb 17, 2026
Data Sourced
via Debian·09:42 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-2064?
CVE-2010-2064 is rated as a high severity vulnerability due to the potential for local privilege escalation.
2
How do I fix CVE-2010-2064?
To fix CVE-2010-2064, you should upgrade rpcbind to version 1.2.5-9 or higher.
3
Who is affected by CVE-2010-2064?
CVE-2010-2064 affects local users on systems running rpcbind version 0.2.0.
4
What type of attack does CVE-2010-2064 exploit?
CVE-2010-2064 exploits a symlink attack to allow local users to write to arbitrary files.
5
Is rpcbind 0.2.0 safe to use in production environments?
No, rpcbind 0.2.0 is not safe to use in production environments due to the risk presented by CVE-2010-2064.