First published: Thu Oct 01 2015(Updated: )
Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAP_CALLIT code.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sun RPCBind | <=0.2.1 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =15.04 | |
Debian GNU/Linux | =7.0 | |
Oracle Solaris SPARC | =10 | |
Oracle Solaris SPARC | =11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7236 has a high severity rating due to its ability to cause a denial of service through daemon crashes.
To fix CVE-2015-7236, update rpcbind to version 0.2.2 or later, as this version addresses the vulnerability.
CVE-2015-7236 affects rpcbind versions up to 0.2.1 and various distributions of Ubuntu, Debian, and Oracle Solaris.
CVE-2015-7236 is classified as a use-after-free vulnerability in the rpcbind service.
Yes, CVE-2015-7236 can be exploited remotely by attackers sending crafted packets to the rpcbind service.