Use-after-free in RPCBind - CVE-2015-7236

 

Use-after-free in RPCBind - CVE-2015-7236

Published: November 30, -0001 / Updated: July 16, 2018


Vulnerability identifier: #VU2752
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-7236
CWE-ID: CWE-416
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to use-after-free error in xprt_set_caller() function in rpcb_svc_com.c in rpcbind 0.2.1 and earlier. A remote attacker can cause a denial of service (daemon crash) via specially crafted packets that involve PMAP_CALLIT code.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

RPCBind
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
Junos OS
Fedora
rpcbind (Alpine package)
rpcbind
Dell EMC Unisphere Central

How to mitigate CVE-2015-7236

Install patch from vendor's website.

RPCBind - update to 0.2.2
rpcbind (Alpine package) - addressed in versions 0.2.1-r2, 0.2.1-r3
Junos OS - addressed in versions 12.1X46-D67, 12.3X48-D55, 12.3R12-S10, 14.1X53-D47, 15.1F5-S5, 15.1F6-S1, 15.1F7, 15.1X49-D110, 15.1X53-D47, 15.1X53-D59, 15.1X53-D60, 15.1X53-D233, 15.1X53-D470, 15.1R4-S5, 15.1R5, 16.1R2, 16.2R1
rpcbind - addressed in versions 0.2.3-0.3.fc22, 0.2.3-0.4.fc23
Dell EMC Unisphere Central - update to 4.0.7

External References

Related Security Bulletins