> Package: rpcbind > Version: 0.2.3-0.6 > Severity: wishlist > > There's a newer version of rpcbind available at: > https://sourceforge.net/projects/rpcbind/ >
I think it's the best to wait until 0.2.5 has been released, as it fixes CVE-2017-8779 "rpcbomb" in a proper way

