LWN.net Logo

OpenAFS potential remote code execution vulnerability

Package(s):openafs CVE #(s):
Created:August 14, 2002 Updated:August 14, 2002
Description: The OpenAFS database server is subject to the integer overflow bug in code derived from the SunRPC library.

This bug could be exploited to crash certain OpenAFS servers (volserver, vlserver, ptserver, buserver) or to obtain unauthorized root access to a host running one of these processes.

Felix von Leitner, discovered this potential division by zero bug in code derived from the SunRPC library which is used in many places including openafs.

Updating now is recommended.

CERT/CC Vulnerability Note VU#192995 Integer overflow in xdr_array() function when deserializing the XDR stream

Alerts:
Debian DSA-142-1 2002-08-05

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds