summaryrefslogtreecommitdiffstats
path: root/meta/recipes-extended/rpcbind/rpcbind_0.2.2.bb
diff options
context:
space:
mode:
authorLi Zhou <li.zhou@windriver.com>2015-11-17 02:18:32 -0500
committerRichard Purdie <richard.purdie@linuxfoundation.org>2016-03-03 11:11:40 +0000
commitd4b6c1657bde83f1267a4fef6b645bf0a64d31d1 (patch)
treea55cb0d8487655f15bef53b425ed0067accbcd81 /meta/recipes-extended/rpcbind/rpcbind_0.2.2.bb
parent854c2e724d0aeb19f390e3ac2e7b40c94b2d383b (diff)
downloadpoky-d4b6c1657bde83f1267a4fef6b645bf0a64d31d1.tar.gz
rpcbind: Security Advisory - rpcbind - CVE-2015-7236
rpcbind: Fix memory corruption in PMAP_CALLIT code Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAP_CALLIT code. The patch comes from <http://www.openwall.com/lists/oss-security/2015/09/18/7>, and it hasn't been in rpcbind upstream yet. (From OE-Core master rev: cc4f62f3627f3804907e8ff9c68d9321979df32b) (From OE-Core rev: 224bcc2ead676600bcd9e290ed23d9b2ed2f481e) (From OE-Core rev: 16cf2f5386bc438dc20c4ae40de267618e9dc500) Signed-off-by: Li Zhou <li.zhou@windriver.com> Signed-off-by: Wenzong Fan <wenzong.fan@windriver.com> Signed-off-by: Ross Burton <ross.burton@intel.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> Signed-off-by: Robert Yang <liezhi.yang@windriver.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> Signed-off-by: Armin Kuster <akuster@mvista.com> Signed-off-by: Joshua Lock <joshua.g.lock@intel.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta/recipes-extended/rpcbind/rpcbind_0.2.2.bb')
-rw-r--r--meta/recipes-extended/rpcbind/rpcbind_0.2.2.bb1
1 files changed, 1 insertions, 0 deletions
diff --git a/meta/recipes-extended/rpcbind/rpcbind_0.2.2.bb b/meta/recipes-extended/rpcbind/rpcbind_0.2.2.bb
index 1952b2a298..486073e28c 100644
--- a/meta/recipes-extended/rpcbind/rpcbind_0.2.2.bb
+++ b/meta/recipes-extended/rpcbind/rpcbind_0.2.2.bb
@@ -16,6 +16,7 @@ SRC_URI = "${SOURCEFORGE_MIRROR}/rpcbind/rpcbind-${PV}.tar.bz2 \
16 file://rpcbind.conf \ 16 file://rpcbind.conf \
17 file://rpcbind.socket \ 17 file://rpcbind.socket \
18 file://rpcbind.service \ 18 file://rpcbind.service \
19 file://cve-2015-7236.patch \
19 " 20 "
20 21
21UCLIBCPATCHES_libc-uclibc = "file://0001-uclibc-nss.patch \ 22UCLIBCPATCHES_libc-uclibc = "file://0001-uclibc-nss.patch \