It was found that due to the way rpcbind uses libtirpc (libntirpc), a memory leak can occur when parsing specially crafted XDR messages. An attacker sending thousands of messages to rpcbind could cause its memory usage to grow without bound, eventually causing it to be terminated by the OOM killer. (CVE-2017-8779) SL7 x86_64 rpcbind-0.2.0-38.el7_3.x86_64.rpm rpcbind-debuginfo-0.2.0- [More...]. Synopsis: Important: rpcbind security update Advisory ID: SLSA-2017:1262-1 Issue Date: 2017-05-21 CVE Numbers: CVE-2017-8779 -- Security Fix(es): * It was found that due to the way rpcbind uses libtirpc (libntirpc), a memory leak can occur when parsing specially crafted XDR messages. An attacker sending thousands of messages to rpcbind could cause its memory usage to grow without bound, eventually causing it to be terminated by the OOM killer. (CVE-2017-8779) -- SL7 x86_64 rpcbind-0.2.0-38.el7_3.x86_64.rpm rpcbind-debuginfo-0.2.0-38.el7_3.x86_64.rpm - Scientific Linux Development Team . Important rpcbind upgrade for Scientific Linux resolves memory exhaustion problems caused by maliciously designed messages to avert OOM crashes.. rpcbind Memory Leak, Security Update, Scientific Linux Advisory, XDR Messages, Remote Exploit. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.