FreeBSD : FreeBSD -- rpcbind(8) remote denial of service [REVISED] (0e5d6969-600a-11e6-a6c3-14dae9d210b8)

Medium Nessus Plugin ID 92896


The remote FreeBSD host is missing one or more security-related updates.


In rpcbind(8), netbuf structures are copied directly, which would result in two netbuf structures that reference to one shared address buffer. When one of the two netbuf structures is freed, access to the other netbuf structure would result in an undefined result that may crash the rpcbind(8) daemon. Impact : A remote attacker who can send specifically crafted packets to the rpcbind(8) daemon can cause it to crash, resulting in a denial of service condition.


Update the affected packages.

See Also

Plugin Details

Severity: Medium

ID: 92896

File Name: freebsd_pkg_0e5d6969600a11e6a6c314dae9d210b8.nasl

Version: $Revision: 2.2 $

Type: local

Published: 2016/08/12

Modified: 2016/10/19

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P


Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:FreeBSD, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info, Settings/ParanoidReport

Patch Publication Date: 2016/08/11

Vulnerability Publication Date: 2015/09/29

Reference Information

CVE: CVE-2015-7236

FreeBSD: SA-15:24.rpcbind