PT-2013-1207 · Openafs · Openafs

Alex Chernyakhovsky

+3

·

Published

2013-11-05

·

Updated

2016-08-24

·

CVE-2013-4134

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenAFS versions prior to 1.4.15 OpenAFS versions 1.6.x prior to 1.6.5 OpenAFS versions 1.7.x prior to 1.7.26
Description The issue is related to the use of weak encryption, specifically DES, for Kerberos keys in OpenAFS. This weakness makes it easier for remote attackers to obtain the service key, potentially leading to breaches of confidentiality, integrity, and availability of protected information. The exploitation of these weaknesses can be done remotely.
Recommendations For OpenAFS versions prior to 1.4.15, update to version 1.4.15 or later. For OpenAFS versions 1.6.x prior to 1.6.5, update to version 1.6.5 or later. For OpenAFS versions 1.7.x prior to 1.7.26, update to version 1.7.26 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09679
CVE-2013-4134
DSA-2729-1

Affected Products

Openafs