PT-2009-1098 · Openafs · Openafs

Derrick Brashear

+2

·

Publicado

2009-04-09

·

Atualizado

2014-04-07

·

CVE-2009-1251

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenAFS versions 1.0 through 1.4.8 OpenAFS versions 1.5.0 through 1.5.58
Description The issue is related to a heap-based buffer overflow in the cache manager of the client in OpenAFS, which can be exploited by remote attackers. This can be achieved by sending an RX response containing more data than specified in a request, potentially leading to a denial of service or the execution of arbitrary code. The vulnerability is associated with the use of XDR arrays. Multiple vulnerabilities in the OpenAFS package can lead to breaches of confidentiality, integrity, and availability of protected information, and these vulnerabilities can be exploited remotely.
Recommendations For OpenAFS versions 1.0 through 1.4.8, update to version 1.4.9 or later. For OpenAFS versions 1.5.0 through 1.5.58, update to version 1.5.59 or later. As a temporary workaround, consider restricting access to the cache manager to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09403
BDU:2015-09679
CVE-2009-1251
DSA-1768-1

Produtos afetados

Openafs