Advisories ยป MGASA-2015-0383

Updated rpcbind packages fix CVE-2015-7236

Publication date: 25 Sep 2015
Modification date: 25 Sep 2015
Type: security
Affected Mageia releases : 5
CVE: CVE-2015-7236

Description

Updated rpcbind package fixes security vulnerability:

A remotely triggerable use-after-free vulnerability was found in rpcbind, a
server that converts RPC program numbers into universal addresses. A remote
attacker can take advantage of this flaw to mount a denial of service (rpcbind
crash) (CVE-2015-7236).
                

References

SRPMS

5/core