Jump to content

Advisories MDVSA-2009:099-1: openafs


paul
 Share

Recommended Posts

Multiple vulnerabilities has been found and corrected in openafs:

 

The cache manager in the client in OpenAFS 1.0 through 1.4.8 and

1.5.0 through 1.5.58 on Linux allows remote attackers to cause a

denial of service (system crash) via an RX response with a large

error-code value that is interpreted as a pointer and dereferenced,

related to use of the ERR_PTR macro (CVE-2009-1250).

 

Heap-based buffer overflow in the cache manager in the client in

OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms

allows remote attackers to cause a denial of service (system crash)

or possibly execute arbitrary code via an RX response containing

more data than specified in a request, related to use of XDR arrays

(CVE-2009-1251).

 

The updated packages have been patched to correct these issues.

 

Update:

 

Packages for 2008.0 are being provided due to extended support for

Corporate products.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...