CVE-2015-7236: Use After Free
Published Oct 1, 2015
·Updated
Use-after-free vulnerability in xprtsetcaller in rpcbsvccom.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAPCALLIT code.
Affected Software
7 affected components
Rpcbind Project Rpcbind<=0.2.1
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.04
Debian Debian Linux=7.0
Oracle Solaris=10
Oracle Solaris=11.3
Event History
Oct 1, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7236?
CVE-2015-7236 has a high severity rating due to its ability to cause a denial of service through daemon crashes.
2
How do I fix CVE-2015-7236?
To fix CVE-2015-7236, update rpcbind to version 0.2.2 or later, as this version addresses the vulnerability.
3
Which systems are affected by CVE-2015-7236?
CVE-2015-7236 affects rpcbind versions up to 0.2.1 and various distributions of Ubuntu, Debian, and Oracle Solaris.
4
What type of vulnerability is CVE-2015-7236?
CVE-2015-7236 is classified as a use-after-free vulnerability in the rpcbind service.
5
Can CVE-2015-7236 be exploited remotely?
Yes, CVE-2015-7236 can be exploited remotely by attackers sending crafted packets to the rpcbind service.