4.3
CVSSv2

CVE-2007-6599

Published: 04/01/2008 Updated: 26/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Race condition in fileserver in OpenAFS 1.3.50 up to and including 1.4.5 and 1.5.0 up to and including 1.5.27 allows remote malicious users to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which causes the handler for the GiveUpAllCallBacks RPC to perform linked-list operations without the host_glock lock.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openafs openafs

debian debian linux 3.1

debian debian linux 4.0

Vendor Advisories

A race condition in the OpenAFS fileserver allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which causes the handler for the GiveUpAllCallBacks RPC to perform linked-list operations without the host_glock lock For the old stable distribution (sarge), this problem has ...