Updated rpcbind packages fix CVE-2015-7236
Publication date: 25 Sep 2015Modification date: 25 Sep 2015
Type: security
Affected Mageia releases : 5
CVE: CVE-2015-7236
Description
Updated rpcbind package fixes security vulnerability: A remotely triggerable use-after-free vulnerability was found in rpcbind, a server that converts RPC program numbers into universal addresses. A remote attacker can take advantage of this flaw to mount a denial of service (rpcbind crash) (CVE-2015-7236).
References
SRPMS
5/core
- rpcbind-0.2.2-1.1.mga5