CVE-2010-2064

EUVD-2010-2083
rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
Affected Products (NVD)
VendorProductVersion
rpcbind_projectrpcbind
0.2.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rpcbind
bookworm
1.2.6-6
fixed
bullseye
1.2.5-9
fixed
sid
1.2.6-8.1
fixed
trixie
1.2.6-8.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rpcbind
hardy
dne
lucid
ignored
maverick
not-affected
natty
not-affected
oneiric
ignored
precise
not-affected
quantal
ignored
raring
ignored
saucy
ignored
trusty
not-affected
utopic
ignored
vivid
not-affected