Untriaged
Activity log
- Created suggestion
rpcbind 0.2.0 allows local users to write to arbitrary files …
rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr.
References
-
-
-
-
[oss-security] 20100608 CVE Request -- rpcbind -- Insecure (predictable) temporary file use mailing-listx_transferredx_refsource_MLIST
Affected products
rpcbind
- ==0.2.0
Package maintainers
-
@abbradar Nikolay Amiantov <ab@fmap.me>