OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache partition, (2) fileserver vice partition, or (3) certain RPC responses.
References
| Link | Resource |
|---|---|
| https://www.openafs.org/pages/security/OPENAFS-SA-2016-003.txt | Vendor Advisory |
| http://www.securityfocus.com/bid/94651 | Third Party Advisory VDB Entry |
| http://www.openwall.com/lists/oss-security/2016/12/02/9 | Mailing List Patch Third Party Advisory |
Configurations
Information
Published : 2017-02-06 09:59
Updated : 2017-02-08 10:46
NVD link : CVE-2016-9772
Mitre link : CVE-2016-9772
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
openafs
- openafs


