CVE-2015-7236

Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAP_CALLIT code.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
microfocusCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
rpcbind_projectrpcbind
𝑥
≤ 0.2.1
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
15.04
debiandebian_linux
7.0
oraclesolaris
11.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rpcbind
bullseye
1.2.5-9
fixed
bookworm
1.2.6-6
fixed
sid
1.2.6-8.1
fixed
trixie
1.2.6-8.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rpcbind
vivid
Fixed 0.2.1-6ubuntu3.1
released
trusty
Fixed 0.2.1-2ubuntu2.2
released
precise
Fixed 0.2.0-7ubuntu1.3
released
References