Guillem Jover pointed out: [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583435#5
a deficiency in the way rpcbind gathered / saved registrations from / to dumped file(s). A local attacker could use this flaw to conduct symbolic link attacks, leading to un-authorized disclosure of sensitive information and / or to important system files data integrity corruption.
CVE Request: [2] http://www.openwall.com/lists/oss-security/2010/06/03/4
rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr.