Candidate: CVE-2014-2852 PublicDate: 2014-04-14 15:09:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2852 http://www.openafs.org/frameset/dl/openafs/1.6.7/ChangeLog http://www.debian.org/security/2014/dsa-2899 Description: OpenAFS before 1.6.7 delays the listen thread when an RXS_CheckResponse fails, which allows remote attackers to cause a denial of service (performance degradation) via an invalid packet. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_openafs: upstream_openafs: released (1.6.7-1) lucid_openafs: ignored (reached end-of-life) precise_openafs: not-affected (1.6.1-1+ubuntu0.4) quantal_openafs: ignored (reached end-of-life) saucy_openafs: ignored (reached end-of-life) trusty_openafs: not-affected (1.6.7-1) trusty/esm_openafs: DNE (trusty was not-affected [1.6.7-1]) utopic_openafs: not-affected (1.6.7-1) vivid_openafs: not-affected (1.6.7-1) devel_openafs: not-affected (1.6.7-1)