Integer overflow in ptserver in OpenAFS before 1.6.2 allows remote attackers to cause a denial of service (crash) via a large list from the IdToName RPC, which triggers a heap-based buffer overflow.
References
Link | Resource |
---|---|
http://www.openafs.org/pages/security/OPENAFS-SA-2013-002.txt | Vendor Advisory |
http://secunia.com/advisories/52480 | Permissions Required Third Party Advisory |
http://secunia.com/advisories/52342 | Permissions Required Third Party Advisory |
http://www.debian.org/security/2013/dsa-2638 | |
http://www.securityfocus.com/bid/58300 | Third Party Advisory VDB Entry |
http://www.mandriva.com/security/advisories?name=MDVSA-2014:244 | Broken Link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/82585 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-03-13 20:13
Updated : 2017-08-28 18:33
NVD link : CVE-2013-1795
Mitre link : CVE-2013-1795
JSON object : View
CWE
CWE-189
Numeric Errors
Products Affected
openafs
- openafs