Show filters
41 Total Results
Displaying 11-20 of 41
Sort by:
Attacker Value
Unknown
CVE-2018-16948
Disclosure Date: September 12, 2018 (last updated November 27, 2024)
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several RPC server routines did not fully initialize their output variables before returning, leaking memory contents from both the stack and the heap. Because the OpenAFS cache manager functions as an Rx server for the AFSCB service, clients are also susceptible to information leakage. For example, RXAFSCB_TellMeAboutYourself leaks kernel memory and KAM_ListEntry leaks kaserver memory.
0
Attacker Value
Unknown
CVE-2018-16947
Disclosure Date: September 12, 2018 (last updated November 27, 2024)
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not require (or allow for) authentication of those RPCs. Handling those RPCs results in operations being performed with administrator credentials, including dumping/restoring volume contents and manipulating the backup database. For example, an unauthenticated attacker can replace any volume's content with arbitrary data.
0
Attacker Value
Unknown
CVE-2017-17432
Disclosure Date: December 06, 2017 (last updated November 26, 2024)
OpenAFS 1.x before 1.6.22 does not properly validate Rx ack packets, which allows remote attackers to cause a denial of service (system crash or application crash) via crafted fields, as demonstrated by an integer underflow and assertion failure for a small MTU value.
0
Attacker Value
Unknown
CVE-2016-9772
Disclosure Date: February 06, 2017 (last updated November 26, 2024)
OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache partition, (2) fileserver vice partition, or (3) certain RPC responses.
0
Attacker Value
Unknown
CVE-2016-4536
Disclosure Date: May 13, 2016 (last updated November 25, 2024)
The client in OpenAFS before 1.6.17 does not properly initialize the (1) AFSStoreStatus, (2) AFSStoreVolumeStatus, (3) VldbListByAttributes, and (4) ListAddrByAttributes structures, which might allow remote attackers to obtain sensitive memory information by leveraging access to RPC call traffic.
0
Attacker Value
Unknown
CVE-2016-2860
Disclosure Date: May 13, 2016 (last updated November 08, 2023)
The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intended access restrictions and create arbitrary groups as administrators by leveraging mishandling of the creator ID.
0
Attacker Value
Unknown
CVE-2015-8312
Disclosure Date: May 13, 2016 (last updated November 08, 2023)
Off-by-one error in afs_pioctl.c in OpenAFS before 1.6.16 might allow local users to cause a denial of service (memory overwrite and system crash) via a pioctl with an input buffer size of 4096 bytes.
0
Attacker Value
Unknown
CVE-2015-7762
Disclosure Date: November 06, 2015 (last updated October 05, 2023)
rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure when constructing an Rx acknowledgement (ACK) packet, which allows remote attackers to obtain sensitive information by (1) conducting a replay attack or (2) sniffing the network.
0
Attacker Value
Unknown
CVE-2015-7763
Disclosure Date: November 06, 2015 (last updated October 05, 2023)
rx/rx.c in OpenAFS 1.5.75 through 1.5.78, 1.6.x before 1.6.15, and 1.7.x before 1.7.33 does not properly initialize padding at the end of an Rx acknowledgement (ACK) packet, which allows remote attackers to obtain sensitive information by (1) conducting a replay attack or (2) sniffing the network.
0
Attacker Value
Unknown
CVE-2015-6587
Disclosure Date: September 02, 2015 (last updated October 05, 2023)
The vlserver in OpenAFS before 1.6.13 allows remote authenticated users to cause a denial of service (out-of-bounds read and crash) via a crafted regular expression in a VL_ListAttributesN2 RPC.
0