Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Debian 8 DSA-3569-1 Moderate: OpenAFS DoS and Group Management Issues

debian
Calendar Grey May 5, 2016
Scroller Debian
Discover the latest about two OpenAFS vulnerabilities in Debian Security Advisory DSA-3569-1, detailing critical flaws and essential updates for user protection
Two vulnerabilities were discovered in openafs, an implementation of the distributed filesystem AFS

Summary

CVE-2015-8312

Potential denial of service caused by a bug in the pioctl
logic allowing a local user to overrun a kernel buffer with a
single NUL byte.

CVE-2016-2860

Peter Iannucci discovered that users from foreign Kerberos realms
can create groups as if they were administrators.

For the stable distribution (jessie), these problems have been fixed in
version 1.6.9-2+deb8u5.

For the testing distribution (stretch), these problems have been fixed
in version 1.6.17-1.

For the unstable distribution (sid), these problems have been fixed in
version 1.6.17-1.

We recommend that you upgrade your openafs packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Package: openafs
CVE ID: CVE-2015-8312 CVE-2016-2860

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.