Search CVE reports


Toggle filters

1 – 5 of 5 results


CVE-2017-8779

Medium priority

Some fixes available 5 of 17

rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data size during memory allocation for XDR strings, which allows remote attackers to cause a...

3 affected packages

rpcbind, libtirpc, ntirpc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rpcbind Not affected Not affected Not affected Fixed
libtirpc Not affected Not affected Not affected Not affected
ntirpc Not affected Not affected Not affected Not affected
Show less packages

CVE-2015-7236

Medium priority
Fixed

Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAP_CALLIT code.

1 affected package

rpcbind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rpcbind
Show less packages

CVE-2012-3541

Low priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

2 affected packages

nfs-utils, rpcbind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nfs-utils
rpcbind
Show less packages

CVE-2010-2064

Low priority
Ignored

rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr.

1 affected package

rpcbind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rpcbind
Show less packages

CVE-2010-2061

Low priority
Ignored

rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr, which can be created by an attacker before the daemon is started.

1 affected package

rpcbind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rpcbind
Show less packages