Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2013-1794
Disclosure Date: March 14, 2013 (last updated October 05, 2023)
Buffer overflow in certain client utilities in OpenAFS before 1.6.2 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long fileserver ACL entry.
0
Attacker Value
Unknown
CVE-2013-1795
Disclosure Date: March 14, 2013 (last updated October 05, 2023)
Integer overflow in ptserver in OpenAFS before 1.6.2 allows remote attackers to cause a denial of service (crash) via a large list from the IdToName RPC, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2007-1507
Disclosure Date: March 20, 2007 (last updated October 04, 2023)
The default configuration in OpenAFS 1.4.x before 1.4.4 and 1.5.x before 1.5.17 supports setuid programs within the local cell, which might allow attackers to gain privileges by spoofing a response to an AFS cache manager FetchStatus request, and setting setuid and root ownership for files in the cache.
0