oss-sec mailing list archives



CVE Request: remote triggerable use-after-free in rpcbind

Hi, One of our customers saw rpcbind crashing on a remote security scan. Olaf Kirch identified and fixed the problem: http://www.spinics.net/lists/linux-nfs/msg53045.html https://bugzilla.suse.com/show_bug.cgi?id=946204 It so far has not been integrated into rpcbind upstream. This is a use-after-free, so at least remote denial of service. We have not researched further exploitability. Ciao, Marcus

By Date By Thread

Current thread: