Untriaged
Activity log
- Created suggestion
rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) …
rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr, which can be created by an attacker before the daemon is started.
References
-
-
-
-
[oss-security] 20100608 CVE Request -- rpcbind -- Insecure (predictable) temporary file use mailing-listx_transferredx_refsource_MLIST
-
Affected products
rpcbind
- ==0.2.0
Package maintainers
-
@abbradar Nikolay Amiantov <ab@fmap.me>