remote denial-of-service

Bug #1687930 reported by Guido
260
This bug affects 2 people
Affects Status Importance Assigned to Milestone
rpcbind (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

It is possible to consume any amount of memory on an rpcbind server with a remote attack. This can affect the stability of the entire system.

Write-up: https://guidovranken.wordpress.com/2017/05/03/rpcbomb-remote-rpcbind-denial-of-service-patches/
Exploit + Patches: https://github.com/guidovranken/rpcbomb/

CVE References

Revision history for this message
Nish Aravamudan (nacc) wrote :
information type: Public → Public Security
Changed in rpcbind (Ubuntu):
status: New → Confirmed
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.