Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Ubuntu 15.04 LTS USN-2756-1 Moderate: Rpcbind Remote Code Execution

Ubuntu Large Esm H500
rpcbind could be made to crash or run programs if it received specially crafted network traffic.
=========================================================================Ubuntu Security Notice USN-2756-1
September 30, 2015

rpcbind vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

rpcbind could be made to crash or run programs if it received specially
crafted network traffic.

Software Description:
- rpcbind: converts RPC program numbers into universal addresses

Details:

It was discovered that rpcbind incorrectly handled certain memory
structures. A remote attacker could use this issue to cause rpcbind to
crash, resulting in a denial of service, or possibly execute arbitrary
code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.04:
  rpcbind                         0.2.1-6ubuntu3.1

Ubuntu 14.04 LTS:
  rpcbind                         0.2.1-2ubuntu2.2

Ubuntu 12.04 LTS:
  rpcbind                         0.2.0-7ubuntu1.3

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2756-1
  CVE-2015-7236

Package Information:
  https://launchpad.net/ubuntu/+source/rpcbind/0.2.1-6ubuntu3.1
  https://launchpad.net/ubuntu/+source/rpcbind/0.2.1-2ubuntu2.2
  https://launchpad.net/ubuntu/+source/rpcbind/0.2.0-7ubuntu1.3


Ubuntu 15.04 LTS USN-2756-1 Moderate: Rpcbind Remote Code Execution

ubuntu
Calendar Grey September 30, 2015
Dist Ubuntu Esm H88
Cautionary notice for Ubuntu regarding rpcbind weakness that may cause system failures and expose to remote code execution threats.
rpcbind could be made to crash or run programs if it received specially crafted network traffic.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: rpcbind 0.2.1-6ubuntu3.1 Ubuntu 14.04 LTS: rpcbind 0.2.1-2ubuntu2.2 Ubuntu 12.04 LTS: rpcbind 0.2.0-7ubuntu1.3 After a standard system update you need to reboot your computer to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2756-1

CVE-2015-7236

Severity
important
Lowest
Low
Medium
High
Critical

September 30, 2015

Package Information

https://launchpad.net/ubuntu/+source/rpcbind/0.2.1-6ubuntu3.1 https://launchpad.net/ubuntu/+source/rpcbind/0.2.1-2ubuntu2.2 https://launchpad.net/ubuntu/+source/rpcbind/0.2.0-7ubuntu1.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here