FS#46341 - [rpcbind] CVE-2015-7236: use-after-free in rpcbind
Attached to Project:
Arch Linux
Opened by Remi Gacogne (rgacogne) - Friday, 18 September 2015, 13:53 GMT
Last edited by Andreas Radke (AndyRTR) - Saturday, 19 September 2015, 16:58 GMT
Opened by Remi Gacogne (rgacogne) - Friday, 18 September 2015, 13:53 GMT
Last edited by Andreas Radke (AndyRTR) - Saturday, 19 September 2015, 16:58 GMT
|
Details
Hi,
A use-after-free has been found [0] in rpcbind, leading at least to a remote denial of service. The issue has not been fixed upstream yet, but a patch has been made available [1] by SuSE, and I think we should backport it until a new version is available. [0]: http://www.openwall.com/lists/oss-security/2015/09/17/1 [1]: http://seclists.org/oss-sec/2015/q3/581 |
This task depends upon
Closed by Andreas Radke (AndyRTR)
Saturday, 19 September 2015, 16:58 GMT
Reason for closing: Fixed
Additional comments about closing: 0.2.3-2
Saturday, 19 September 2015, 16:58 GMT
Reason for closing: Fixed
Additional comments about closing: 0.2.3-2