Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian: DSA-3388-1 Important: OpenAFS Remote Exploit Vulnerability

debian
Calendar Grey November 1, 2015
Debian Logo
The latest security patch for OpenAFS addresses vulnerabilities in packet handling, ensuring that sensitive plaintext information is safeguarded in Debian builds.
John Stumpo discovered that OpenAFS, a distributed file system, does not fully initialize certain network packets before transmitting them

Summary

John Stumpo discovered that OpenAFS, a distributed file system, does
not fully initialize certain network packets before transmitting them.
This can lead to a disclosure of the plaintext of previously processed
packets.

For the oldstable distribution (wheezy), these problems have been fixed
in version 1.6.1-3+deb7u5.

For the stable distribution (jessie), these problems have been fixed in
version 1.6.9-2+deb8u4.

For the testing distribution (stretch) and the unstable distribution
(sid), these problems have been fixed in version 1.6.15-1.

We recommend that you upgrade your openafs packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: openafs
CVE ID: CVE-2015-7762 CVE-2015-7763

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here