diff options
author | Li Zhou <li.zhou@windriver.com> | 2015-11-17 02:18:32 -0500 |
---|---|---|
committer | Robert Yang <liezhi.yang@windriver.com> | 2015-12-08 00:18:12 -0800 |
commit | 224bcc2ead676600bcd9e290ed23d9b2ed2f481e (patch) | |
tree | 8012389a129774e41b33a5594d226db41abdb19f /scripts/lib/devtool/standard.py | |
parent | e1e277bf51c6f00268358f6bf8623261b1b9bc22 (diff) | |
download | openembedded-core-224bcc2ead676600bcd9e290ed23d9b2ed2f481e.tar.gz openembedded-core-224bcc2ead676600bcd9e290ed23d9b2ed2f481e.tar.bz2 openembedded-core-224bcc2ead676600bcd9e290ed23d9b2ed2f481e.zip |
rpcbind: Security Advisory - rpcbind - CVE-2015-7236
rpcbind: Fix memory corruption in PMAP_CALLIT code
Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in
rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of
service (daemon crash) via crafted packets, involving a PMAP_CALLIT
code.
The patch comes from
<http://www.openwall.com/lists/oss-security/2015/09/18/7>, and it hasn't
been in rpcbind upstream yet.
(From OE-Core master rev: cc4f62f3627f3804907e8ff9c68d9321979df32b)
Signed-off-by: Li Zhou <li.zhou@windriver.com>
Signed-off-by: Wenzong Fan <wenzong.fan@windriver.com>
Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Robert Yang <liezhi.yang@windriver.com>
Diffstat (limited to 'scripts/lib/devtool/standard.py')
0 files changed, 0 insertions, 0 deletions