Re: [BLFS Trac] #23370: rpcbind-1.2.9
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23370: rpcbind-1.2.9
-------------------------+------------------------
Reporter: Bruce Dubbs | Owner: blfs-book
Type: enhancement | Status: new
Priority: elevated | Milestone: 13.1
Component: BOOK | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+------------------------
Changes (by Douglas R. Reno):
* priority: normal => elevated
Comment:
Yeouch.
{{{
rpcinfo: stack buffer overflow in rpcinfo rpcbaddrlist()
rpcinfo's rpcbaddrlist() formats two server-controlled, unbounded XDR
strings into a
fixed 128-byte stack buffer with sprintf(). A malicious or on-path rpcbind
server
overflows it when a user runs:
rpcinfo -l <host> <prognum> <versnum>
}}}
There are also memory leak fixes in here, but "rpcbind: Stop
unauthenticated oversized allocation in PMAPPROC_CALLIT decode" is also
notable.
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23370#comment:1>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page