4
CVSSv2

CVE-2015-6587

Published: 02/09/2015 Updated: 02/09/2015
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

The vlserver in OpenAFS prior to 1.6.13 allows remote authenticated users to cause a denial of service (out-of-bounds read and crash) via a crafted regular expression in a VL_ListAttributesN2 RPC.

Vulnerable Product Search on Vulmon Subscribe to Product

openafs openafs

debian debian linux 7.0

debian debian linux 8.0

Vendor Advisories

It was discovered that OpenAFS, the implementation of the distributed filesystem AFS, contained several flaws that could result in information leak, denial-of-service or kernel panic For the oldstable distribution (wheezy), these problems have been fixed in version 161-3+deb7u3 For the stable distribution (jessie), these problems have been fixe ...