openafs: denial of service
| Package(s): | openafs |
CVE #(s): | CVE-2015-6587
|
| Created: | September 8, 2015 |
Updated: | September 10, 2015 |
| Description: |
From the Mageia advisory:
The vlserver allows pattern matching on volume names via regular expressions
when listing attributes. Because the regular expression is not checked for
situations which can overflow the buffers used, an attack is possible which
reads arbitrary memory beyond the end of the buffer and can act on it as part
of the expression evaluation, potentially crashing the process. |
| Alerts: |
|