|
|
Log in / Subscribe / Register

openafs: denial of service

Package(s):openafs CVE #(s):CVE-2015-6587
Created:September 8, 2015 Updated:September 10, 2015
Description: From the Mageia advisory:

The vlserver allows pattern matching on volume names via regular expressions when listing attributes. Because the regular expression is not checked for situations which can overflow the buffers used, an attack is possible which reads arbitrary memory beyond the end of the buffer and can act on it as part of the expression evaluation, potentially crashing the process.

Alerts:
Debian-LTS DLA-342-1 openafs 2015-11-18
Mageia MGASA-2015-0337 openafs 2015-09-08

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds