This service uses the function xdr_array() of the RPC library. It turns out that some older versions of the RPC library are vulnerable to an integer overflow in this function, which could allow an attacker to gain root privileges on this host.
*** No security hole regarding this program has been tested, so *** this might be a false positive.