PT-2013-1208 · Openafs · Openafs

Chaskiel M Grundman

+1

·

Publicado

2013-11-05

·

Atualizado

2016-08-24

·

CVE-2013-4135

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenAFS versions 1.6.x through 1.6.4 OpenAFS version 1.6.5 and later are not affected, but since the issue is with versions before 1.6.5, we can simplify to: OpenAFS versions prior to 1.6.5
Description The issue allows remote attackers to obtain sensitive information by sniffing the network due to the vos command in OpenAFS only enabling integrity protection and sending data in cleartext when using the -encrypt option. Multiple vulnerabilities in the OpenAFS package may lead to violations of confidentiality, integrity, and availability of protected information, and these can be exploited remotely.
Recommendations For OpenAFS versions prior to 1.6.5, update to version 1.6.5 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the -encrypt option with the vos command until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09679
CVE-2013-4135
DSA-2729-1

Produtos afetados

Openafs